Vulnerability Description
WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/contact-forms-builder/
- https://www.exploit-db.com/exploits/50734
- https://www.vulncheck.com/advisories/wordpress-contact-form-builder-cross-site-s
FAQ
What is CVE-2022-50959?
CVE-2022-50959 is a vulnerability with a CVSS score of 6.1 (MEDIUM). WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Atta...
How severe is CVE-2022-50959?
CVE-2022-50959 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50959?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.