WordPress security by component
Forms by CaptainForm – Form Builder for WordPress
Plugin description
Forms by CaptainForm – Form Builder for WordPress is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Dec 15, 2023; the highest published CVSS base score is 7.1.
Plugin slug:
captainformLatest vulnerability
CVE-2023-49170: Forms by CaptainForm – Form Builder for WordPress: Cross-site scripting
Forms by CaptainForm – Form Builder for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Dec 15, 2023 |
CVE-2023-49170
Forms by CaptainForm – Form Builder for WordPress: Cross-site scripting
Forms by CaptainForm – Form Builder for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 28, 2023 |
CVE-2022-43459
Captainform: Cross-site request forgery
Captainform is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD8.8
|