CVE-2023-4950
WordPress vulnerability analysis and mitigation

Overview

The Interactive Contact Form and Multi Step Form Builder WordPress plugin (Funnelforms Free) before version 3.4 contains a stored Cross-Site Scripting (XSS) vulnerability. The vulnerability was discovered and disclosed in September 2023, affecting all versions of the plugin prior to 3.4. The issue stems from the plugin's failure to properly sanitize and escape certain parameters, potentially exposing WordPress installations to XSS attacks (WPScan).

Technical details

The vulnerability exists due to improper input validation where the plugin fails to sanitize and escape parameters in form submissions. The issue specifically affects the name field in contact forms, allowing malicious scripts to be stored and executed. The vulnerability has been assigned a CVSS score of 6.1 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network accessibility with low attack complexity and no privileges required (NVD).

Impact

When exploited, this vulnerability allows unauthenticated users to inject malicious scripts through form submissions. These scripts are stored in the database and executed when administrators view the submissions in the 'Leads' section of the WordPress dashboard, potentially leading to unauthorized actions being performed with administrator privileges (WPScan).

Mitigation and workarounds

The vulnerability has been patched in version 3.4 of the Funnelforms Free plugin. Site administrators are strongly advised to update to this version or later to protect against potential XSS attacks. If immediate updating is not possible, administrators should carefully monitor form submissions and consider temporarily disabling the plugin until it can be updated (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13542CRITICAL9.8
  • designthemes-lms
NoYesDec 02, 2025
CVE-2025-13724HIGH7.5
  • vikrentcar
NoYesDec 02, 2025
CVE-2025-13731MEDIUM6.4
  • nexter-extension
NoYesDec 02, 2025
CVE-2025-12630MEDIUM4.9
  • upload-am-file-hosting-vpn
NoYesDec 02, 2025
CVE-2025-13090MEDIUM4.9
  • wpdirectorykit
NoYesDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management