CVE-2022-50959
MEDIUMWordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2022-50959. PoCs published by Milad karimi.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in WordPress Plugin Contact Form Builder 1.6.1 via the 'form_id' parameter in 'code_generator.php'. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.
Description
WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in WordPress Plugin Contact Form Builder 1.6.1 via the 'form_id' parameter in 'code_generator.php'. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N