PT-2023-16352 · WordPress · Contact-Form-Plugin

Vaibhav Rajput

·

Publicado

2023-04-10

·

Atualizado

2023-04-14

·

CVE-2023-0546

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contact Form Plugin WordPress plugin versions prior to 4.3.25
Description The issue allows a logged-in user with roles as low as contributor to inject arbitrary JavaScript into a form. This can be achieved by exploiting the improper sanitization and escaping of the srcdoc attribute in iframes within the plugin's custom HTML field type. The injected JavaScript will trigger for any visitor to the form or for admins previewing or editing the form.
Recommendations For versions prior to 4.3.25, update to version 4.3.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the custom HTML field type in the Contact Form Plugin to prevent potential exploitation until the update can be applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-0546

Produtos afetados

Contact-Form-Plugin