First published: Mon May 15 2023(Updated: )
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
nCrafts FormCraft | <=1.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22717 is considered a critical vulnerability due to its potential for stored cross-site scripting and its impact on user data.
To fix CVE-2023-22717, update the nCrafts FormCraft plugin to version 1.2.7 or later immediately.
CVE-2023-22717 affects versions of the nCrafts FormCraft plugin up to and including 1.2.6.
Website administrators and users of WordPress sites that utilize the vulnerable nCrafts FormCraft plugin are impacted by CVE-2023-22717.
CVE-2023-22717 is associated with stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.