CVE-2021-36821: WordPress Forminator plugin <= 1.14.11 - Stored Cross-Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.
Other sources
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin <= 1.14.11 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36821?
The severity of CVE-2021-36821 is high.
What is the affected software by CVE-2021-36821?
The affected software by CVE-2021-36821 is WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin versions <= 1.14.11.
What is the vulnerability in CVE-2021-36821?
CVE-2021-36821 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability.
How can I fix the vulnerability in CVE-2021-36821?
To fix the vulnerability in CVE-2021-36821, update the WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin to version 1.14.12 or higher.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-36821?
The Common Weakness Enumeration (CWE) ID for CVE-2021-36821 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').