First published: Fri Apr 07 2023(Updated: )
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cimatti Contact Forms WordPress | <1.5.5 |
Update to 1.5.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28781 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the Cimatti Consulting WordPress Contact Forms plugin.
CVE-2023-28781 allows attackers to inject malicious scripts into the contact forms of your WordPress website, potentially leading to unauthorized actions or information theft.
CVE-2023-28781 has a severity rating of high (6.1).
To fix CVE-2023-28781, you should update the Cimatti Consulting WordPress Contact Forms plugin to version 1.5.5 or above.
You can find more information about CVE-2023-28781 at the following link: [https://patchstack.com/database/vulnerability/contact-forms/wordpress-contact-forms-by-cimatti-plugin-1-5-4-unauth-stored-cross-site-scripting-xss-vulnerability](https://patchstack.com/database/vulnerability/contact-forms/wordpress-contact-forms-by-cimatti-plugin-1-5-4-unauth-stored-cross-site-scripting-xss-vulnerability)