CVE-2023-4950 PUBLISHED CVSS 8.5 HIGH

The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks

EPSS 0.55% · 67.7th percentile

Risk Scores

CVSS v4.0
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.55%
67.7th percentile

Affected Products

VendorProductVersions
UnknownInteractive Contact Form and Multi Step Form Builder with Drag & Drop Editor0, 0, 0
funnelformsfunnelforms0, 0, 0

Timeline

References

Open in Interactive Console →