CVE-2023-0084

HIGH

Metform Elementor Contact Form Builder <3.1.2 - XSS

Title source: llm

Description

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, which is the submissions page.

Exploits (1)

exploitdb WRITEUP
by Mohammed Chemouri · textwebappsphp
https://www.exploit-db.com/exploits/51204

Scores

CVSS v3 7.2
EPSS 0.4784
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
roxnor/MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor < 3.1.2
wpmet/metform_elementor_contact_form_builder < 3.1.2
Published Mar 02, 2023
Tracked Since Feb 18, 2026