Cross-Site Scripting in Metform Elementor Contact Form Builder for WordPress
CVE-2023-0709
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 June 2023
What is CVE-2023-0709?
The Metform Elementor Contact Form Builder for WordPress is susceptible to Cross-Site Scripting (XSS) due to improper handling of the 'mf_last_name' shortcode, which echoes unescaped user submissions. This vulnerability affects versions up to and including 3.3.0. Authenticated attackers with contributor-level permissions can exploit this flaw to inject malicious scripts, which may execute when unsuspecting users visit a constructed link containing the submission ID. The injected script is stored within the website's database, adding to the risk.
Affected Version(s)
Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress * <= 3.3.0