CVE-2023-51536: WordPress CRM Perks Forms Plugin <= 1.1.2 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress Form Builder: from n/a through 1.1.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51536?
CVE-2023-51536 is classified as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2023-51536?
To fix CVE-2023-51536, update the CRM Perks Forms plugin to version 1.1.3 or later.
Which version of CRM Perks Forms is affected by CVE-2023-51536?
CVE-2023-51536 affects CRM Perks Forms from any version up to and including 1.1.2.
What impact does CVE-2023-51536 have on users?
CVE-2023-51536 can allow attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data.
Is there a workaround for CVE-2023-51536?
Currently, the only reliable method to mitigate CVE-2023-51536 is to update the affected plugin to a fixed version.