The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
As a contributor, put the following in a blog post, and preview it: [zohoForms src='" onload="alert(1)"'] [zohoForms src='http://localhost/" onmouseover="alert(1)"']
Lana Codes
Lana Codes
Yes
2023-01-23 (about 4 months ago)
2023-01-23 (about 4 months ago)
2023-01-23 (about 4 months ago)