CVE-2023-0439
NEX-Forms < 8.4.4 - Authenticated Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.
The NEX-Forms - Ultimate Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form names parameter in versions up to, and including, 8.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin has the option to allow lower-level users access to the form, which may make this issue exploitable by lower-privileged users in some instances.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-01-23 CVE Reserved
- 2023-06-26 CVE Published
- 2024-10-30 CVE Updated
- 2024-10-30 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/04cea9aa-b21c-49f8-836b-2d312253e09a | 2024-10-30 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Basixonline Search vendor "Basixonline" | Nex-forms Search vendor "Basixonline" for product "Nex-forms" | < 8.4.4 Search vendor "Basixonline" for product "Nex-forms" and version " < 8.4.4" | wordpress |
Affected
|