CVE-2023-0439: NEX-Forms < 8.4.4 - Authenticated Stored XSS
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0439?
CVE-2023-0439 has been classified as a medium severity vulnerability due to the potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2023-0439?
To mitigate CVE-2023-0439, you should update the NEX-Forms WordPress plugin to version 8.4.4 or later.
Who is affected by CVE-2023-0439?
CVE-2023-0439 affects users of the NEX-Forms WordPress plugin prior to version 8.4.4.
What kind of attack can CVE-2023-0439 lead to?
CVE-2023-0439 can lead to Stored Cross-Site Scripting (XSS) attacks, allowing an attacker to execute malicious scripts.
Is there a patch for CVE-2023-0439?
Yes, the vulnerability can be patched by updating the NEX-Forms plugin to version 8.4.4 or higher.