WordPress Plugin Vulnerabilities

Multi Step Form <= 1.2.5 - Multiple Unauthenticated Reflected XSS

Description

WordPress Plugin Multi Step Form before 1.2.5 allows remote users to execute JavaScript code through Reflected XSS attacks.

This issue can be exploited by unauthenticated attackers, by the use of CSRF, for example.

Proof of Concept

Affects Plugins

Fixed in 1.2.6

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Javier Olmedo
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2018-07-20 (about 7 years ago)
Added
2018-07-30 (about 7 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other