CVE-2023-37988: WordPress Contact Form Generator Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)
Published Aug 10, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.
Affected Software
1 affected component
creative-solutions Contact Form Generator Wordpress<=2.5.5
Remediation
Information
Update to 2.6.0 or a higher version.
Event History
Aug 10, 2023
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-37988?
The severity of CVE-2023-37988 is high (6.1).
2
What is the affected software for CVE-2023-37988?
The affected software for CVE-2023-37988 is the Creative Solutions Contact Form Generator plugin <= 2.5.5.
3
How does CVE-2023-37988 impact websites?
CVE-2023-37988 allows for unauthorized reflected cross-site scripting (XSS) attacks, which can lead to the execution of malicious script code on the targeted user's browser.
4
Are there any patches or fixes available for CVE-2023-37988?
Yes, a patch has been released for CVE-2023-37988. It is recommended to update the Creative Solutions Contact Form Generator plugin to version 2.5.6 or later.
5
What is the CWE category for CVE-2023-37988?
The CWE category for CVE-2023-37988 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).