CVE-2023-0695: Metform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf shortcode
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a specific link. Note that getting the JavaScript to execute still requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-0695.
What is the title of the vulnerability?
The title of the vulnerability is 'The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by us…'
What is the severity of CVE-2023-0695?
The severity of CVE-2023-0695 is medium with a severity value of 5.4.
What software is affected by CVE-2023-0695?
The Metform Elementor Contact Form Builder plugin for WordPress up to and including version 3.3.0 is affected by CVE-2023-0695.
How can an attacker exploit CVE-2023-0695?
Authenticated attackers with contributor-level permissions or above can exploit CVE-2023-0695 by using the 'mf' shortcode to echo unescaped form submissions.