WordPress Plugin Vulnerabilities

FormBuilder <= 1.08 - Stored Cross-Site Scripting via CSRF

Description

The plugin does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Miscellaneous

Original Researcher
Chiragh Arora
Submitter
Chiragh Arora
Verified
Yes

Timeline

Publicly Published
2022-03-08 (about 3 years ago)
Added
2022-03-08 (about 3 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other