The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NWpforms Pirate Forms
APPWpforms< 2.6.0
Powiązane podatności
CSV Injection w WPForms Pro — brak walidacji danych eksportu
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission paramete...
The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘pub...
WPForms 1.7.8 zawiera lukę typu cross-site scripting w funkcji importu suwaka oraz parametrze tab. Atakujący m...