First published: Wed May 31 2023(Updated: )
The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks CRM Perks Forms | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-2836.
The title of the vulnerability is 'The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form setti...'
The severity of CVE-2023-2836 is medium with a CVSS score of 4.8.
The vulnerability in the CRM Perks Forms plugin allows authenticated attackers with administrator-level permissions to execute stored cross-site scripting attacks via form settings.
To fix the CVE-2023-2836 vulnerability, update the CRM Perks Forms plugin to a version above 1.1.1 that includes input sanitization and output escaping.