First published: Thu Mar 16 2023(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forminator | <1.14.12 |
Update to 1.14.12 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36821 is high.
The affected software by CVE-2021-36821 is WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin versions <= 1.14.11.
CVE-2021-36821 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability.
To fix the vulnerability in CVE-2021-36821, update the WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin to version 1.14.12 or higher.
The Common Weakness Enumeration (CWE) ID for CVE-2021-36821 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').