CVE-2023-44230: WordPress Popup contact form Plugin <= 7.1 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44230?
CVE-2023-44230 is an authentication (admin+) stored Cross-Site Scripting (XSS) vulnerability in the Gopi Ramasamy Popup contact form plugin version 7.1 and below.
What is the severity of CVE-2023-44230?
The severity of CVE-2023-44230 is medium, with a severity value of 4.8.
How does CVE-2023-44230 affect the Gopi Ramasamy Popup contact form plugin?
CVE-2023-44230 affects the Gopi Ramasamy Popup contact form plugin version 7.1 and below, allowing stored Cross-Site Scripting (XSS) attacks.
Is there a fix available for CVE-2023-44230?
Yes, a fix is available for CVE-2023-44230. It is recommended to update the Gopi Ramasamy Popup contact form plugin to a version higher than 7.1.
Where can I find more information about CVE-2023-44230?
More information about CVE-2023-44230 can be found at the following reference: [https://patchstack.com/database/vulnerability/popup-contact-form/wordpress-popup-contact-form-plugin-7-1-cross-site-scripting-xss-2?_s_id=cve].