WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
Vulnerability Description
WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50959
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Milad karimi
References
More from wpdevart
View All →Affected Vendor
wpdevart
View all reports →