High severity7.1NVD Advisory· Published Aug 10, 2023· Updated Jun 17, 2026
CVE-2023-37988
CVE-2023-37988
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:creative-solutions:contact_form_generator:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:creative-solutions:contact_form_generator:*:*:*:*:*:wordpress:*:*range: <=2.5.5
- (no CPE)range: n/a
- Range: <=2.5.5
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/174896/WordPress-Contact-Form-Generator-2.5.5-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- patchstack.com/database/vulnerability/contact-form-generator/wordpress-contact-form-generator-plugin-2-5-5-reflected-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
News mentions
0No linked articles in our index yet.