CVE-2023-30500: WordPress WPForms plugins - Reflected Cross Site Scripting (XSS) vulnerability
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-30500?
CVE-2023-30500 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in the WPForms Lite and WPForms Pro plugins.
What software is affected by CVE-2023-30500?
WPForms WPForms Lite (wpforms-lite) plugin versions up to 1.8.1.2 and WPForms WPForms Pro (wpforms) plugin versions up to 1.8.1.2 are affected by CVE-2023-30500.
What is the severity of CVE-2023-30500?
CVE-2023-30500 has a severity rating of 6.1, which is considered medium.
How can I fix the CVE-2023-30500 vulnerability?
To fix the CVE-2023-30500 vulnerability, update WPForms Lite (wpforms-lite) plugin to version 1.8.1.2 or higher and update WPForms Pro (wpforms) plugin to version 1.8.1.2 or higher.
What is Cross-Site Scripting (XSS) vulnerability?
Cross-Site Scripting (XSS) is a type of vulnerability that allows an attacker to inject malicious scripts into web pages viewed by users.