VYPR
Unrated severityNVD Advisory· Published Mar 23, 2023· Updated Apr 28, 2026

WordPress Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration Plugin <= 1.62.0 is vulnerable to Cross Site Scripting (XSS)

CVE-2022-47173

Description

Stored XSS vulnerability in AFI plugin versions ≤ 1.62.0 allows admin-level attackers to inject malicious scripts via stored form integration settings.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in AFI plugin versions ≤ 1.62.0 allows admin-level attackers to inject malicious scripts via stored form integration settings.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the Advanced Form Integration plugin for WordPress, versions 1.62.0 and earlier [1]. The issue resides in the plugin's admin-facing form integration configuration pages, where user-supplied input is not properly sanitized before being stored and later rendered. An attacker with admin-level privileges can inject arbitrary web scripts into saved settings, which are then executed in the context of the admin dashboard [1].

Exploitation

An attacker must have administrator-level access to the WordPress site (Auth. admin+) [1]. No further user interaction is required beyond saving the malicious configuration. The attacker navigates to the plugin's settings page, inserts malicious JavaScript payloads into vulnerable input fields (e.g., integration labels or mapping fields), and saves the configuration. Any subsequent admin user who views the affected settings page will trigger the stored payload [1].

Impact

Successful exploitation leads to stored cross-site scripting (XSS) [1]. This allows the attacker to execute arbitrary JavaScript in the context of another administrator's session. Impact may include privilege escalation, session hijacking, forced administrative actions, or defacement of the admin interface. The compromise is confined to the admin dashboard and does not directly affect site visitors [1].

Mitigation

A fix is available in plugin version 1.132.1 or later, released after the vulnerable 1.62.0 version [1]. Users should update to the latest version immediately. No workaround is disclosed in the available references. The plugin is actively maintained on the WordPress plugin repository. This CVE is not known to be listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.