cleantalk
Vulnerabilities and Security Researches

Contact Form Email, CVE-2023-2718

CVE, Research URL

CVE-2023-2718

Application

Contact Form Email

Published on
Jun 12, 2023
Research Description
The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.
Affected versions
max 1.3.38.
Status
vulnerable