WordPress ApplyOnline – Application Form Builder and Manager Plugin <= 2.5.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-45756
7.1HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 25 October 2023
Summary
This vulnerability allows an unauthenticated attacker to exploit reflected cross-site scripting (XSS) in the Spider Teams ApplyOnline plugin. By crafting a malicious request, attackers can execute scripts in the context of the affected users' browsers, potentially compromising user data and session security. It affects versions up to 2.5.2, making it crucial for users to implement necessary security measures.
Affected Version(s)
ApplyOnline – Application Form Builder and Manager <= 2.5.2
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Le Ngoc Anh (Patchstack Alliance)