CVE-2023-50836: WordPress HTML Forms Plugin <= 1.3.28 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibericode HTML Forms allows Stored XSS.This issue affects HTML Forms: from n/a through 1.3.28.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50836?
CVE-2023-50836 is classified as a high-severity vulnerability due to its potential for causing stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2023-50836?
To fix CVE-2023-50836, update the Ibericode HTML Forms plugin to the latest version above 1.3.28.
What are the potential impacts of CVE-2023-50836?
CVE-2023-50836 can allow attackers to inject malicious scripts into web pages viewed by users, leading to sensitive data theft.
Which versions of HTML Forms are affected by CVE-2023-50836?
CVE-2023-50836 affects Ibericode HTML Forms from any version up to and including 1.3.28.
Is user input impacted by CVE-2023-50836?
Yes, CVE-2023-50836 directly relates to improper neutralization of user input during web page generation, leading to stored XSS vulnerabilities.