QID 730782

Date Published: 2023-04-10

QID 730782: WordPress Plugin Zoho Forms Stored Cross-Site Scripting (XSS) Vulnerability

Zoho Forms WordPress plugin create beautiful forms for your website in minutes.

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected Versions:
Zoho Forms WordPress plugin versions prior to 3.0.1

QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Zoho Forms plugin.

Successful exploitation of this vulnerability may allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to install Zoho Forms 3.0.1 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730782

    Software Advisories
    Advisory ID Software Component Link
    Zoho Forms Plugin Release Notes URL Logo wordpress.org/plugins/zoho-forms/#developers