First published: Fri Dec 29 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho Forms | <=3.0.1 |
Update to 3.0.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50891 is considered a moderate severity cross-site scripting vulnerability.
To fix CVE-2023-50891, update the Zoho Forms plugin for WordPress to a version above 3.0.1.
CVE-2023-50891 involves an improper neutralization of input during web page generation, allowing stored cross-site scripting (XSS) attacks.
CVE-2023-50891 affects all versions of Zoho Forms for WordPress up to and including 3.0.1.
Yes, CVE-2023-50891 poses a serious security risk as it allows attackers to inject malicious scripts into web pages.