CVE-2023-48752: WordPress Happyforms Plugin <= 1.25.9 is vulnerable to Cross Site Scripting (XSS)
Published Nov 30, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms allows Reflected XSS.This issue affects Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms: from n/a through 1.25.9.
Affected Software
1 affected component
Happyforms Happyforms WordPress<=1.25.9
Event History
Nov 30, 2023
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the WordPress Happyforms Plugin vulnerability?
The vulnerability ID is CVE-2023-48752.
2
What is the severity score of CVE-2023-48752?
The severity score is 7.1 (high).
3
What is the CWE ID for CVE-2023-48752?
The CWE ID is 79.
4
How does CVE-2023-48752 affect the Happyforms plugin?
CVE-2023-48752 allows for Cross-Site Scripting (XSS) attacks in the Happyforms plugin.
5
How can I fix CVE-2023-48752 in the WordPress Happyforms Plugin?
To fix CVE-2023-48752 in the WordPress Happyforms Plugin, update to version 1.25.10 or later.