CVE-2023-32498: WordPress Easy Form by AYS Plugin <= 1.2.0 is vulnerable to Cross Site Scripting (XSS)
Published Aug 23, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Easy Form team Easy Form by AYS plugin <= 1.2.0 versions.
Affected Software
1 affected component
ays-pro Easy Form Wordpress<=1.2.0
Remediation
Information
Update to 1.2.1 or a higher version.
Event History
Aug 23, 2023
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-32498?
CVE-2023-32498 is a Stored Cross-Site Scripting (XSS) vulnerability in the Easy Form plugin for WordPress, specifically version 1.2.0 and earlier.
2
How severe is CVE-2023-32498?
CVE-2023-32498 has a severity score of 4.8, which is considered medium.
3
What is the affected software of CVE-2023-32498?
The Easy Form plugin by AYS, versions up to and including 1.2.0, are affected by CVE-2023-32498.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-32498?
CVE-2023-32498 is associated with CWE-79, which is the classification for Cross-Site Scripting (XSS) vulnerabilities.
5
How can I fix CVE-2023-32498?
To fix CVE-2023-32498, update the Easy Form plugin to a version later than 1.2.0 where the vulnerability is patched.