PT-2023-16352 · WordPress · Contact-Form-Plugin
Vaibhav Rajput
·
Publicado
2023-04-10
·
Atualizado
2023-04-14
·
CVE-2023-0546
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Contact Form Plugin WordPress plugin versions prior to 4.3.25
Description
The issue allows a logged-in user with roles as low as contributor to inject arbitrary JavaScript into a form. This can be achieved by exploiting the improper sanitization and escaping of the
srcdoc attribute in iframes within the plugin's custom HTML field type. The injected JavaScript will trigger for any visitor to the form or for admins previewing or editing the form.Recommendations
For versions prior to 4.3.25, update to version 4.3.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the custom HTML field type in the Contact Form Plugin to prevent potential exploitation until the update can be applied.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Contact-Form-Plugin