CVE-2023-2718
12.06.2023, 18:15
The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.
| Vendor | Product | Version |
|---|---|---|
| codepeople | contact_form_email | 𝑥 < 1.3.38 |
𝑥
= Vulnerable software versions
References