First published: Mon Oct 25 2021(Updated: )
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Formidable Forms | <5.0.07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24608 is rated as a medium severity vulnerability due to the potential for exploit through Cross-Site Scripting attacks.
To fix CVE-2021-24608, update the Formidable Form Builder plugin to version 5.0.07 or later.
CVE-2021-24608 exploits improper sanitization and escaping of form labels used in the Formidable Form Builder plugin.
Users of the Formidable Form Builder plugin for WordPress who have versions prior to 5.0.07 are affected by CVE-2021-24608.
CVE-2021-24608 can enable high privileged users to perform Cross-Site Scripting attacks.