CVE-2023-3248: All-in-one Floating Contact Form < 2.1.2 - Admin+ Stored Cross-Site Scripting
The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3248.
What is the severity of CVE-2023-3248?
The severity of CVE-2023-3248 is medium.
How does CVE-2023-3248 impact the All-in-one Floating Contact Form WordPress plugin?
CVE-2023-3248 allows high privilege users, such as admin, to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Which version of the All-in-one Floating Contact Form WordPress plugin is affected by CVE-2023-3248?
The All-in-one Floating Contact Form WordPress plugin version up to and excluding 2.1.2 is affected by CVE-2023-3248.
Is there a fix available for CVE-2023-3248?
Yes, updating the All-in-one Floating Contact Form WordPress plugin to version 2.1.2 or later will fix CVE-2023-3248.