CVE-2023-2301: Contact Form Builder by vcita <= 4.10.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.3. This is due to missing nonce validation on the lsparsevcitacallback function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. While the Cross-Site Scripting issue was patched in version 4.10.1, the plugin is still technically vulnerable to Cross-Site Request Forgery since a capability check but no nonce check was added in 4.10.2.
Other sources
The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.1. This is due to missing nonce validation on the lsparsevcitacallback function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-2301?
CVE-2023-2301 is a vulnerability in the Contact Form Builder by vcita plugin for WordPress that allows unauthenticated attackers to perform Cross-Site Request Forgery.
What is the severity of CVE-2023-2301?
CVE-2023-2301 has a severity rating of 6.1, which is considered medium.
How does CVE-2023-2301 affect the Contact Form Builder by vcita plugin for WordPress?
CVE-2023-2301 affects versions up to and including 4.9.1 of the Contact Form Builder by vcita plugin for WordPress by allowing unauthenticated attackers to modify the plugin's settings.
How can I fix CVE-2023-2301?
To fix CVE-2023-2301, it is recommended to update the Contact Form Builder by vcita plugin for WordPress to a version higher than 4.9.1.
Where can I find more information about CVE-2023-2301?
More information about CVE-2023-2301 can be found at the following references: [link1], [link2], [link3].