WordPress ApplyOnline – Application Form Builder and Manager Plugin <= 2.5.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-45756

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
25 October 2023

Summary

This vulnerability allows an unauthenticated attacker to exploit reflected cross-site scripting (XSS) in the Spider Teams ApplyOnline plugin. By crafting a malicious request, attackers can execute scripts in the context of the affected users' browsers, potentially compromising user data and session security. It affects versions up to 2.5.2, making it crucial for users to implement necessary security measures.

Affected Version(s)

ApplyOnline – Application Form Builder and Manager <= 2.5.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.