CVE-2023-3134: Forminator < 1.24.4 - Reflected XSS
Published Jul 31, 2023
·Updated
The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.
Affected Software
1 affected component
Incsub Forminator Wordpress<1.24.4
Event History
Jul 31, 2023
CVE Published
via MITRE·09:37 AM
Data Sourced
via MITRE·09:37 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Forminator WordPress plugin vulnerability?
The vulnerability ID for this Forminator WordPress plugin vulnerability is CVE-2023-3134.
2
What is the severity of CVE-2023-3134?
The severity of CVE-2023-3134 is medium.
3
How does the Forminator WordPress plugin vulnerability occur?
The Forminator WordPress plugin vulnerability occurs due to improper value escaping in form fields that use pre-populated query parameters, leading to reflected XSS attacks.
4
What is the affected software of CVE-2023-3134?
The affected software of CVE-2023-3134 is the Forminator WordPress plugin before version 1.24.4.
5
How can I fix the CVE-2023-3134 vulnerability?
To fix the CVE-2023-3134 vulnerability, update the Forminator WordPress plugin to version 1.24.4 or newer.