WordPress ApplyOnline – Application Form Builder and Manager Plugin <= 2.5.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-45756

7.1HIGH

What is CVE-2023-45756?

This vulnerability allows an unauthenticated attacker to exploit reflected cross-site scripting (XSS) in the Spider Teams ApplyOnline plugin. By crafting a malicious request, attackers can execute scripts in the context of the affected users' browsers, potentially compromising user data and session security. It affects versions up to 2.5.2, making it crucial for users to implement necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ApplyOnline – Application Form Builder and Manager <= 2.5.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.