MEDIUM🇬🇧 English

CVE-2020-36919

CVSS 5.1v4.0pub. 2026-01-13upd. 2026-01-29

WPForms 1.7.8 zawiera lukę typu cross-site scripting w funkcji importu suwaka oraz parametrze tab. Atakujący mogą wstrzyknąć złośliwe skrypty poprzez endpoint ListTable.php w celu wykonania dowolnego JavaScript w przeglądarce ofiary.

Pokaż oryginał (EN)

WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Wpforms

    APP
    Wpforms
    ≤ 1.7.8
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2024-11205HIGH8.5ten sam produkt

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...

CVE-2023-7063HIGH7.2ten sam produkt

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission paramete...

CVE-2024-13403MEDIUM6.4ten sam produkt

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordP...

CVE-2024-56276MEDIUM4.3ten sam produkt

Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Inco...

CVE-2024-11223MEDIUM4.7ten sam produkt

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could al...