« Volver al listado

CVE-2022-23988

Estado: ModificadaMedia (6.1)—

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23988",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "WS Form",
          "product": "WS Form LITE – Drag & Drop Contact Form Builder for WordPress",
          "versions": [
            {
              "status": "affected",
              "version": "1.8.176",
              "lessThan": "1.8.176",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "WS Form",
          "product": "WS Form Pro",
          "versions": [
            {
              "status": "affected",
              "version": "1.8.176",
              "lessThan": "1.8.176",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-02-28T09:15:09.497",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/9d5738f9-9a2e-4878-8a03-745894420bf6",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/9d5738f9-9a2e-4878-8a03-745894420bf6",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "contact@wpscan.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission"
    },
    {
      "lang": "es",
      "value": "Los plugins WS Form LITE y Pro WordPress versiones anteriores a 1.8.176, no sanean ni escapan de los datos del formulario enviado, permitiendo a un atacante no autenticado enviar cargas útiles de tipo XSS que serán ejecutadas cuando un usuario con privilegios visualice el envío correspondiente."
    }
  ],
  "lastModified": "2026-06-17T04:31:06.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:westguardsolutions:ws_form:*:*:*:*:lite:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D60DAD5B-15C3-46F1-9322-63B4BBBCEBE6",
              "versionEndExcluding": "1.8.176"
            },
            {
              "criteria": "cpe:2.3:a:westguardsolutions:ws_form:*:*:*:*:pro:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "120F355B-8EA8-4ED1-909D-25595B0CBFA5",
              "versionEndExcluding": "1.8.176"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}