CVE-2023-37982: WordPress Integration for Contact Form 7 and Salesforce Plugin <= 1.3.3 is vulnerable to Open Redirection
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.3.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37982?
CVE-2023-37982 is classified as a moderate severity vulnerability.
How do I fix CVE-2023-37982?
To fix CVE-2023-37982, update the Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms to version 1.3.4 or later.
What kind of vulnerability is CVE-2023-37982?
CVE-2023-37982 is an 'Open Redirect' vulnerability that allows redirecting users to untrusted sites.
Which versions are affected by CVE-2023-37982?
CVE-2023-37982 affects all versions of the Integration for Salesforce and Contact Form 7, WPForms, Elementor, Ninja Forms up to and including version 1.3.3.
Are there any mitigations for CVE-2023-37982?
Temporary mitigation for CVE-2023-37982 includes disabling the affected plugins until they are updated.