s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-28781

📛 CVE Title

WordPress Contact Forms by Cimatti Plugin <= 1.5.4 is vulnerable to Cross Site Scripting (XSS)

Description

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
HIGH
CVSS score
CVSS 7.1 / 10 7.1 7.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Effective score
7.1 / 10 HIGH source: CNA overview
CWE(s)
CWE-79
Reserved
2023-03-23
Published
2023-04-07 16:08 UTC
Last updated
2026-04-28 18:08 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/28xxx/CVE-2023-28781.json
Linked Threat
CVE-2023-28781 — WordPress Contact Forms by Cimatti <= 1.5.4 - Unauthenticated Stored Cross-Site Scripting

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-32416
Assigner
Patchstack
Published
Apr 7, 2023, 2:08:39 PM
Updated
Apr 28, 2026, 4:08:16 PM
EUVD base score (CVSS 3.1)
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EUVD-reported EPSS
0.2000
Vendors
Cimatti Consulting
Products
WordPress Contact Forms by Cimatti (n/a ≤1.5.4)
Aliases
GHSA-c2c7-r6r9-3c2v

ENISA description: Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
Cimatti Consulting WordPress Contact Forms by Cimatti n/a (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2023-28781 no local data 2026-06-06 15:09 UTC

Flagged vendors

    Remediations (16)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:github.com

      WadesWeaponShed / CVE -2026-50751- Mitigation -Scripts Public Notifications You must be signed in to change notification settings Fork 0 Star 1

      2026-06-10 16:34 UTC
    • web:www.microsoft.com

      Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.

      2026-06-10 16:34 UTC
    • web:knowledge.broadcom.com

      The intent of this article is to help customers that are using VMware vSphere 8.x address the most critical security vulnerabilities. Broadcom will provide all perpetual license customers, including those that have expired support contracts, with access to zero-day security patches, which are defined by Broadcom as patches for Critical Severity Security Alerts with a Common Vulnerability ...

      2026-06-10 16:34 UTC
    • web:nvd.nist.gov

      An official website of the United States government Here's how you know

      2026-06-10 16:34 UTC
    • web:zecurit.com

      Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

      2026-06-10 16:34 UTC
    • Wordfence remediation: Contact Forms by Cimatti
      Wordfence

      Update to version 1.5.5, or a newer patched version

      2026-06-06 15:09 UTC
    • web:www.bugcrowd.com

      Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.

      2026-05-22 06:15 UTC
    • web:www.cisa.gov

      If vulnerabilities cannot be remediated within the recommended timeframes, develop a remediation plan for action and coordination across the organization. The remediation plan should include: Vulnerability remediation constraints Interim mitigation actions to overcome constraints Final actions required to remediate vulnerability

      2026-05-22 06:15 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-05-22 06:15 UTC
    • web:www.secure.com

      Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.

      2026-05-22 06:15 UTC
    • web:translate.google.com

      Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.

      2026-05-22 06:15 UTC
    • web:nvlpubs.nist.gov

      The third version, SP 800-40, Revision 3, Guide to Enterprise Patch Management Technologies (2013), was written under the assumption that readers already understood the basics of patch management and that what they most needed help with was implementing, configuring, securing, and using enterprise patch management technologies.

      2026-05-22 06:15 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 06:15 UTC
    • web:securityboulevard.com

      Cybersecurity vulnerabilities pose significant risks to organizations in today's digital landscape. Left unaddressed, these vulnerabilities can lead to data breaches, financial losses, and reputational damage. Organizations must decide how to tackle vulnerabilities—through remediation , mitigation , or a combination of both. But which strategy is more effective? This blog explores the ...

      2026-05-22 06:15 UTC
    • web:source.android.com

      Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level. Devices that use the 2025-11-01 security patch level must include all issues associated with that security patch level, as well as fixes for all issues reported in previous security bulletins.

      2026-05-22 06:15 UTC
    • web:github.com

      A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.

      2026-05-22 06:15 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2023-28781.json.

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T13:51:38.833Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "https://patchstack.com/database/vulnerability/contact-forms/wordpress-contact-forms-by-cimatti-plugin-1-5-4-unauth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-28781",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T20:49:06.788612Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T21:33:53.457Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "contact-forms",
              "product": "WordPress Contact Forms by Cimatti",
              "vendor": "Cimatti Consulting",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "1.5.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "1.5.4",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "thiennv (Patchstack Alliance)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <=<span style=\"background-color: var(--wht);\">\u00a01.5.4 versions.</span>"
                }
              ],
              "value": "Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <=\u00a01.5.4 versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-592",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-592 Stored XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-28T16:08:16.794Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/vulnerability/contact-forms/wordpress-contact-forms-by-cimatti-plugin-1-5-4-unauth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to\u00a01.5.5 or a higher version."
                }
              ],
              "value": "Update to\u00a01.5.5 or a higher version."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Contact Forms by Cimatti Plugin <= 1.5.4 is vulnerable to Cross Site Scripting (XSS)",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2023-28781",
        "datePublished": "2023-04-07T14:08:39.607Z",
        "dateReserved": "2023-03-23T17:01:46.246Z",
        "dateUpdated": "2026-04-28T16:08:16.794Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }