SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23988

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

MEDIUM 6.1EPSS 2.23%

Does this matter?

Lower severity and a low EPSS score (2.23%). Track it; it rarely justifies an emergency change on its own.

Description

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.23% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
westguardsolutions/ws form
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.