CVE-2023-45070: WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS)
Published Oct 18, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
Affected Software
1 affected component
10web Form Maker Wordpress<1.15.19
Remediation
Information
Update to 1.15.19 or a higher version.
Event History
Oct 18, 2023
CVE Published
via MITRE·12:34 PM
Data Sourced
via MITRE·12:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-45070.
2
What is the title of this vulnerability?
The title of this vulnerability is Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by …
3
What is the affected software?
The affected software is 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin version <= 1.15.18.
4
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.1.
5
How can I fix this vulnerability?
To fix this vulnerability, update the 10Web Form Builder Team Form Maker plugin to version 1.15.19 or higher.