CVE-2022-50959: WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50959?
CVE-2022-50959 is classified as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2022-50959?
To fix CVE-2022-50959, update the WordPress Contact Form Builder plugin to the latest version.
Who is affected by CVE-2022-50959?
CVE-2022-50959 affects users of WordPress Contact Form Builder version 1.6.1.
What attack vectors does CVE-2022-50959 expose?
CVE-2022-50959 exposes attack vectors for unauthenticated attackers to exploit the form_id parameter.
Is CVE-2022-50959 easily exploitable?
CVE-2022-50959 is considered easy to exploit, allowing attackers to inject malicious scripts.