CVE-2021-24513

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/09/2021
Last modified:
09/09/2021

Description

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:web-settler:form_builder:*:*:*:*:*:wordpress:*:* 1.9.8.4 (excluding)