First published: Mon Dec 13 2021(Updated: )
The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attributes. This could allow attackers to make a logged in admin edit arbitrary forms with Cross-Site Scripting payloads in them
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Basix NEX-Forms – Ultimate Form Builder | <=7.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-24705 is rated as medium with a score of 4.8.
To mitigate CVE-2021-24705, it is recommended to update the NEX-Forms plugin to version 8.4.3 or newer.
Attackers could make a logged-in admin edit arbitrary forms with Cross-Site Scripting (XSS) if they exploit CVE-2021-24705.