WS Form LITE and WS Form Pro < 1.8.176 - Stored Cross-Site Scripting
2022-01-31 00:00
Felipe Restrepo Rodriguez (pfelilpe)Strategic Overview
StatusPatched in 1.8.176
Affected PluginWS Form LITE – Drag & Drop Contact Form Builder
Affected Version
< 1.8.176CVSS7.2High
CVE
CVE-2022-23988Vulnerability Overview
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
Technical Analysis
REMEDIATION: Update to version 1.8.176, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C