CVE-2023-5955: Contact Form Email < 1.3.44 - Editor+ Stored Cross-Site Scripting
The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5955?
CVE-2023-5955 has a moderate severity level due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2023-5955?
To fix CVE-2023-5955, update the Contact Form Email plugin to version 1.3.44 or higher.
Who is affected by CVE-2023-5955?
CVE-2023-5955 affects users of the Contact Form Email WordPress plugin prior to version 1.3.44.
What type of attack does CVE-2023-5955 facilitate?
CVE-2023-5955 facilitates Stored Cross-Site Scripting attacks that can be exploited by high privilege users.
Can CVE-2023-5955 be exploited in a restricted user environment?
Yes, CVE-2023-5955 can be exploited by admin users even when the unfiltered_html capability is disallowed.