WordPress Plugin Vulnerabilities

Form Maker by 10Web < 1.13.40 - Authenticated Reflected XSS

Description

The 'Form Maker by 10Web' WordPress plugin is vulnerable to XSS in the 'blocked_ips_fm' page. A logged-in site administrator who follows a crafted link will trigger arbitrary JavaScript code to be run in their browser in the context of their privileged account on the WordPress site.

Proof of Concept

Affects Plugins

Fixed in 1.13.40

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Andy Tyler (@ticarpi)
Submitter
Andy Tyler
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2020-07-12 (about 5 years ago)
Added
2020-07-12 (about 5 years ago)
Last Updated
2020-07-12 (about 5 years ago)

Other