CVE-2023-44265: WordPress Popup contact form Plugin <= 7.1 is vulnerable to Cross Site Scripting (XSS)
Published Oct 2, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions.
Affected Software
1 affected component
gopiplus Popup Contact Form Wordpress<=7.1
Event History
Oct 2, 2023
CVE Published
via MITRE·10:14 AM
Data Sourced
via MITRE·10:14 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-44265.
2
What is the severity level of CVE-2023-44265?
The severity level of CVE-2023-44265 is medium.
3
What is the affected software by CVE-2023-44265?
The affected software by CVE-2023-44265 is Gopi Ramasamy Popup contact form plugin version <= 7.1 for WordPress.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-44265?
The CWE ID associated with CVE-2023-44265 is CWE-79 (Cross-Site Scripting).
5
Are there any patches or fixes available for CVE-2023-44265?
Yes, patches or fixes are available. You can find more information at https://patchstack.com/database/vulnerability/popup-contact-form/wordpress-popup-contact-form-plugin-7-1-cross-site-scripting-xss?_s_id=cve