PT-2023-16352 · WordPress · Contact-Form-Plugin

Vaibhav Rajput

·

Published

2023-04-10

·

Updated

2023-04-14

·

CVE-2023-0546

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contact Form Plugin WordPress plugin versions prior to 4.3.25
Description The issue allows a logged-in user with roles as low as contributor to inject arbitrary JavaScript into a form. This can be achieved by exploiting the improper sanitization and escaping of the srcdoc attribute in iframes within the plugin's custom HTML field type. The injected JavaScript will trigger for any visitor to the form or for admins previewing or editing the form.
Recommendations For versions prior to 4.3.25, update to version 4.3.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the custom HTML field type in the Contact Form Plugin to prevent potential exploitation until the update can be applied.

Exploit

Fix

Related Identifiers

CVE-2023-0546

Affected Products

Contact-Form-Plugin