First published: Thu Jun 22 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPForms Contact Form | <=1.8.1.2 | |
WPForms Contact Form | <=1.8.1.2 |
Update WPForms Lite or WPForms Pro to 1.8.1.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30500 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in the WPForms Lite and WPForms Pro plugins.
WPForms WPForms Lite (wpforms-lite) plugin versions up to 1.8.1.2 and WPForms WPForms Pro (wpforms) plugin versions up to 1.8.1.2 are affected by CVE-2023-30500.
CVE-2023-30500 has a severity rating of 6.1, which is considered medium.
To fix the CVE-2023-30500 vulnerability, update WPForms Lite (wpforms-lite) plugin to version 1.8.1.2 or higher and update WPForms Pro (wpforms) plugin to version 1.8.1.2 or higher.
Cross-Site Scripting (XSS) is a type of vulnerability that allows an attacker to inject malicious scripts into web pages viewed by users.