
Cloud Vulnerability DB
A community-led vulnerabilities database
Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by multiple Cross Site Scripting (XSS) vulnerabilities via various input fields including Business Name, Tax Code, First Name, Address, Town, Phone, Mobile, Place of Birth, Web Site, VAT Number, Last Name, Fax, Email, and Skype fields (NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 5.4 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The vulnerability allows attackers to inject malicious web scripts or HTML code through multiple user input fields that are not properly sanitized or validated before being stored or displayed (NVD).
If successfully exploited, this vulnerability could allow attackers to inject arbitrary web scripts that execute in victims' browsers when they view the affected pages. This could lead to theft of sensitive information, session hijacking, or other malicious actions performed in the context of the affected users' sessions (NVD).
The vulnerability requires an attacker to have low privileges and user interaction for successful exploitation. The attack complexity is low, indicating that the vulnerability is relatively straightforward to exploit once an attacker has the required access (NVD).
Users should update to a patched version of the WP SMART CRM plugin if available. If an update is not available, users should consider implementing additional input validation and output encoding controls, or removing the plugin until a fix is released (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."