S4E just found an informational finding from web sayfası erişilebilirlik kontrolü
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2023-37988

7.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.
Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
contact form generator
Updated Sep 18, 2026View on NVD →
S4E scanner

Contact Form Generator <= 2.5.5 - Cross-Site Scripting

The Contact Form Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in wp-admin/admin.php in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. References: https://packetstorm.news/files/id/174896 https://nvd.nist.gov/vuln/detail/CVE-2023-37988 Remediation: Update to plugin version 2.5.6 or later.

Used 2.8k times · 1 assets checked · domain, subdomain, ipv4

CVE history: contact form generator

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →