CVE-2023-23885: WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS)
Published Apr 7, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
Affected Software
1 affected component
Fullworksplugins Quick Contact Form Wordpress<=8.0.3.1
Remediation
Information
Update to 8.0.4 or a higher version.
Event History
Apr 7, 2023
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23885?
The severity of CVE-2023-23885 is medium.
2
What is the affected software of CVE-2023-23885?
The affected software of CVE-2023-23885 is Fullworks Quick Contact Form plugin version up to and including 8.0.3.1.
3
How can I fix CVE-2023-23885 vulnerability?
To fix the CVE-2023-23885 vulnerability, update to the latest version of the Fullworks Quick Contact Form plugin.
4
What is the Common Weakness Enumeration (CWE) of CVE-2023-23885?
The Common Weakness Enumeration (CWE) of CVE-2023-23885 is CWE-79.
5
Where can I find more information about CVE-2023-23885?
You can find more information about CVE-2023-23885 at [this link](https://patchstack.com/database/vulnerability/quick-contact-form/wordpress-quick-contact-form-plugin-8-0-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve).