CVE-2022-1564: Form Maker By 10Web < 1.14.12 - Admin+ Stored Cross-Site Scripting
Published May 30, 2022
·Updated
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
1 affected component
10web Form Maker Wordpress<=1.14.12
Event History
May 30, 2022
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-1564.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text…'.
3
What is the affected software?
The affected software is the 10Web Form Maker WordPress plugin.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 4.8.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.