CVE-2023-23981: WordPress Conversational Forms for ChatBot Plugin <= 1.1.6 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions.
Affected Software
1 affected component
QuantumCloud Conversational Forms For Chatbot Wordpress<1.1.7
Remediation
Information
Update to 1.1.7 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·04:43 AM
Data Sourced
via MITRE·04:43 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23981?
The severity of CVE-2023-23981 is medium.
2
What is the affected software for CVE-2023-23981?
The affected software for CVE-2023-23981 is QuantumCloud Conversational Forms for ChatBot plugin version up to 1.1.6.
3
What is the Common Weakness Enumeration (CWE) for CVE-2023-23981?
The Common Weakness Enumeration (CWE) for CVE-2023-23981 is CWE-79 (Cross-site Scripting).
4
How can I fix the Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin version up to 1.1.6?
To fix the vulnerability, update QuantumCloud Conversational Forms for ChatBot plugin to version 1.1.7 or higher.
5
Where can I find more information about CVE-2023-23981?
You can find more information about CVE-2023-23981 at the following link: [CVE-2023-23981](https://patchstack.com/database/vulnerability/conversational-forms/wordpress-conversational-forms-for-chatbot-plugin-1-1-6-cross-site-scripting-xss?_s_id=cve)