Stored Cross-Site Scripting Vulnerability in Contact Form Builder by vcita for WordPress
CVE-2023-2300
5.4MEDIUM
What is CVE-2023-2300?
The Contact Form Builder by vcita plugin for WordPress has a vulnerability that allows authenticated users with sufficient privileges to inject malicious scripts through the 'email' parameter. This vulnerability arises from inadequate input sanitization and output escaping, permitting attackers to execute unauthorized web scripts on pages viewed by other users. Attackers with the edit_posts capability, including contributors and above, could leverage this flaw to compromise the integrity of pages using the plugin and potentially gain unauthorized access to sensitive user data.
Affected Version(s)
Contact Form Builder by vcita * <= 4.9.1