VulnerabilityModified
CVE-2022-23988
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
MEDIUM 6.1EPSS 2.23%
Does this matter?
Lower severity and a low EPSS score (2.23%). Track it; it rarely justifies an emergency change on its own.
Description
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.23% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- westguardsolutions/ws form
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/9d5738f9-9a2e-4878-8a03-745894420bf6Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/9d5738f9-9a2e-4878-8a03-745894420bf6Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.