Cross-Site Scripting in Metform Elementor Contact Form Builder for WordPress
CVE-2023-0709

5.4MEDIUM

Summary

The Metform Elementor Contact Form Builder for WordPress is susceptible to Cross-Site Scripting (XSS) due to improper handling of the 'mf_last_name' shortcode, which echoes unescaped user submissions. This vulnerability affects versions up to and including 3.3.0. Authenticated attackers with contributor-level permissions can exploit this flaw to inject malicious scripts, which may execute when unsuspecting users visit a constructed link containing the submission ID. The injected script is stored within the website's database, adding to the risk.

Affected Version(s)

Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress * <= 3.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramuel Gall
.