CVE-2023-25981: WordPress BuddyForms Plugin <= 2.8.1 is vulnerable to Cross Site Scripting (XSS)
Published Aug 25, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions.
Affected Software
1 affected component
Themekraft Post Form Wordpress<=2.8.1
Remediation
Information
Update to 2.8.2 or a higher version.
Event History
Aug 25, 2023
CVE Published
via MITRE·09:54 AM
Data Sourced
via MITRE·09:54 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25981?
CVE-2023-25981 is a Stored Cross-Site Scripting (XSS) vulnerability in the ThemeKraft Post Form plugin.
2
How severe is CVE-2023-25981?
CVE-2023-25981 has a severity rating of medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2023-25981?
The affected software for CVE-2023-25981 is the ThemeKraft Post Form plugin version <= 2.8.1.
4
How can I fix CVE-2023-25981?
To fix CVE-2023-25981, update the ThemeKraft Post Form plugin to a version higher than 2.8.1.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-25981?
The Common Weakness Enumeration (CWE) for CVE-2023-25981 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').