CVE-2023-5119: Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site Scripting
Published Nov 20, 2023
·Updated
The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfilteredhtml capability is disallowed (for example in a multisite setup).
Affected Software
1 affected component
Incsub Forminator Wordpress<1.27.0
Event History
Nov 20, 2023
CVE Published
06:55 PM
Data Sourced
06:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-5119?
The severity of CVE-2023-5119 is medium with a severity value of 4.8.
2
What is the affected software of CVE-2023-5119?
The affected software of CVE-2023-5119 is Forminator and Forminator Pro version up to 1.27.0.
3
How does CVE-2023-5119 affect high-privilege users?
CVE-2023-5119 allows high-privilege users, such as an administrator, to inject arbitrary web scripts.
4
What capability is required for the exploit of CVE-2023-5119?
The unfiltered_html capability is required for the exploit of CVE-2023-5119.
5
Is there a fix available for CVE-2023-5119?
Yes, updating to Forminator and Forminator Pro version 1.27.0 or above fixes CVE-2023-5119.