First published: Tue Nov 23 2021(Updated: )
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forminator | <1.15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Forminator WordPress plugin is CVE-2021-24700.
The severity of CVE-2021-24700 is medium with a severity value of 4.8.
The affected software for CVE-2021-24700 is the Forminator WordPress plugin before version 1.15.4.
The CWE number for CVE-2021-24700 is 79.
High privilege users can exploit CVE-2021-24700 by performing Cross-Site Scripting attacks using the unsanitized and unescaped email field label.