First published: Mon Jul 17 2023(Updated: )
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Basix NEX-Forms – Ultimate Form Builder | <8.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0439 has been classified as a medium severity vulnerability due to the potential for Stored Cross-Site Scripting (XSS) attacks.
To mitigate CVE-2023-0439, you should update the NEX-Forms WordPress plugin to version 8.4.4 or later.
CVE-2023-0439 affects users of the NEX-Forms WordPress plugin prior to version 8.4.4.
CVE-2023-0439 can lead to Stored Cross-Site Scripting (XSS) attacks, allowing an attacker to execute malicious scripts.
Yes, the vulnerability can be patched by updating the NEX-Forms plugin to version 8.4.4 or higher.