WordPress Plugin Vulnerabilities
Form Maker By 10Web < 1.14.12 - Admin+ Stored Cross-Site Scripting
Description
The plugin does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Abhinav Porwal & Hitesh Kumar
Submitter
Abhinav Porwal & Hitesh Kumar
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-05-09 (about 3 years ago)
Added
2022-05-09 (about 3 years ago)
Last Updated
2022-05-09 (about 3 years ago)