Unrated severityNVD Advisory· Published Mar 16, 2023· Updated Apr 28, 2026
WordPress BuddyForms Plugin <= 2.7.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-38971
Description
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ThemeKraft/Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissionsv5Range: n/a
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.