CVE-2023-2718: Contact Form Email < 1.3.38 - Unauthenticated Stored Cross-Site Scripting
Published Jun 12, 2023
·Updated
The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.
Affected Software
1 affected component
CodePeople Contact Form Email Wordpress<1.3.38
Event History
Jun 12, 2023
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2718?
CVE-2023-2718 has a high severity rating due to its potential for Stored XSS attacks.
2
How do I fix CVE-2023-2718?
To fix CVE-2023-2718, update the Contact Form Email WordPress plugin to version 1.3.38 or later.
3
What type of vulnerability is CVE-2023-2718?
CVE-2023-2718 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
4
What versions are affected by CVE-2023-2718?
CVE-2023-2718 affects all versions of the Contact Form Email plugin before 1.3.38.
5
Who is affected by CVE-2023-2718?
Users of the Contact Form Email WordPress plugin prior to version 1.3.38 are affected by CVE-2023-2718.