WordPress ApplyOnline – Application Form Builder and Manager Plugin <= 2.5.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-45756
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 October 2023
What is CVE-2023-45756?
This vulnerability allows an unauthenticated attacker to exploit reflected cross-site scripting (XSS) in the Spider Teams ApplyOnline plugin. By crafting a malicious request, attackers can execute scripts in the context of the affected users' browsers, potentially compromising user data and session security. It affects versions up to 2.5.2, making it crucial for users to implement necessary security measures.
Affected Version(s)
ApplyOnline – Application Form Builder and Manager <= 2.5.2