CVE-2021-24700: Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting
Published Nov 23, 2021
·Updated
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml is disallowed
Affected Software
1 affected component
Incsub Forminator Wordpress<1.15.4
Event History
Nov 23, 2021
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Forminator WordPress plugin?
The vulnerability ID for the Forminator WordPress plugin is CVE-2021-24700.
2
What is the severity of CVE-2021-24700?
The severity of CVE-2021-24700 is medium with a severity value of 4.8.
3
What is the affected software for CVE-2021-24700?
The affected software for CVE-2021-24700 is the Forminator WordPress plugin before version 1.15.4.
4
What is the CWE number for CVE-2021-24700?
The CWE number for CVE-2021-24700 is 79.
5
How can high privilege users exploit CVE-2021-24700?
High privilege users can exploit CVE-2021-24700 by performing Cross-Site Scripting attacks using the unsanitized and unescaped email field label.