CVE-2023-2528: Contact Form by Supsystic <= 1.7.24 - Cross-Site Request Forgery via AJAX action
The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2528?
CVE-2023-2528 is a vulnerability in the Contact Form by Supsystic plugin for WordPress that allows unauthenticated attackers to execute AJAX actions via a Cross-Site Request Forgery (CSRF) attack.
What is the severity of CVE-2023-2528?
CVE-2023-2528 has a severity of 8.8, which is considered high.
How does CVE-2023-2528 impact WordPress websites?
CVE-2023-2528 allows unauthenticated attackers to perform unauthorized actions on WordPress websites that have the vulnerable Contact Form by Supsystic plugin installed.
Is there a fix for CVE-2023-2528?
Yes, updating to version 1.7.25 or later of the Contact Form by Supsystic plugin for WordPress fixes the vulnerability.
Where can I find more information about CVE-2023-2528?
You can find more information about CVE-2023-2528 at the following references: [Link 1](https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/trunk/classes/frame.php?rev=2777737#L297), [Link 2](https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/trunk/classes/frame.php?rev=2912584#L230), [Link 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/1c387b07-baf6-4c62-943e-4bd121160ceb?source=cve).