Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2023-0709

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a a page containing the shortcode when the submission id is present in the query string. Note that getting the JavaScript to execute requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database.

CVSS: MEDIUM (5.4)

EPSS Score: 0.08%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0708

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_name' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a a page containing the shortcode when the submission id is present in the query string. Note that getting the JavaScript to execute requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database.

CVSS: MEDIUM (5.4)

EPSS Score: 0.08%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0695

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-level permissions or above, to inject arbitrary web scripts in pages that will execute when the victim visits a specific link. Note that getting the JavaScript to execute still requires user interaction as the victim must visit a crafted link with the form entry id, but the script itself is stored in the site database.

CVSS: MEDIUM (5.4)

EPSS Score: 0.06%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0694

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form submission.

CVSS: MEDIUM (6.5)

EPSS Score: 0.06%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0692

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of arbitrary form submissions.

CVSS: MEDIUM (4.3)

EPSS Score: 0.06%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0691

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, specifically the submitter's last name.

CVSS: MEDIUM (4.3)

EPSS Score: 0.06%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0688

Description: The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about form submissions, including payment status, and transaction ID.

CVSS: MEDIUM (6.5)

EPSS Score: 0.1%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0584

Description: The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value.

CVSS: MEDIUM (4.3)

EPSS Score: 0.06%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2023-0292

Description: The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS: MEDIUM (5.4)

EPSS Score: 0.61%

Source: CVE
December 21st, 2024 (4 months ago)

CVE-2024-37962

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Fusion allows Stored XSS.This issue affects Fusion: from n/a through 1.6.1.

CVSS: MEDIUM (6.5)

EPSS Score: 0.04%

Source: CVE
December 20th, 2024 (4 months ago)