First published: Mon Oct 25 2021(Updated: )
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vfbpro Visual Form Builder | <3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24514.
The severity of CVE-2021-24514 is medium (4.8).
The affected software of CVE-2021-24514 is the Visual Form Builder WordPress plugin before version 3.0.4.
The Visual Form Builder plugin does not sanitize or escape its Form Name, allowing high privilege users to set Cross-Site Scripting payload in them.
Yes, the vulnerability fix is available in version 3.0.4 of the Visual Form Builder plugin.