Cross-Site Scripting Vulnerability in Metform Elementor Contact Form Builder for WordPress
CVE-2023-0710
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 June 2023
Summary
The Metform Elementor Contact Form Builder plugin for WordPress contains a Cross-Site Scripting vulnerability. This issue arises from the use of the 'fname' attribute within the 'mf_thankyou' shortcode, which allows unescaped form submissions to be echoed. The flaw affects versions up to and including 3.3.0. Authenticated attackers with contributor-level permissions or higher can exploit this vulnerability by injecting arbitrary web scripts into pages where the shortcode is used. These malicious scripts execute when victims visit a page that incorporates the submission ID in the query string. While user interaction is necessary to activate the script by visiting a specially crafted link, the script itself is stored in the site's database, and successful exploitation requires a successful payment, adding to the complexity of the attack.
Affected Version(s)
Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress * <= 3.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved