cleantalk
Vulnerabilities and Security Researches

Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder, CVE-2021-24718

CVE, Research URL

CVE-2021-24718

Published on
Dec 06, 2021
Research Description
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Affected versions
Min -, max 1.5.
Status
vulnerable