Cross-Site Scripting Vulnerability in Metform Elementor Contact Form Builder for WordPress
CVE-2023-0710

4.9MEDIUM

Summary

The Metform Elementor Contact Form Builder plugin for WordPress contains a Cross-Site Scripting vulnerability. This issue arises from the use of the 'fname' attribute within the 'mf_thankyou' shortcode, which allows unescaped form submissions to be echoed. The flaw affects versions up to and including 3.3.0. Authenticated attackers with contributor-level permissions or higher can exploit this vulnerability by injecting arbitrary web scripts into pages where the shortcode is used. These malicious scripts execute when victims visit a page that incorporates the submission ID in the query string. While user interaction is necessary to activate the script by visiting a specially crafted link, the script itself is stored in the site's database, and successful exploitation requires a successful payment, adding to the complexity of the attack.

Affected Version(s)

Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress * <= 3.3.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramuel Gall
.