First published: Fri Apr 07 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cimatti Contact Forms WordPress | <1.5.5 |
Update to 1.5.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-28789.
The title of the vulnerability is Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms.
The affected software is Cimatti Consulting WordPress Contact Forms plugin version 1.5.4 and below.
The severity of CVE-2023-28789 is high (6.1).
To fix the CVE-2023-28789 vulnerability, you should update the Cimatti Consulting WordPress Contact Forms plugin to version 1.5.5 or later.