cleantalk
Vulnerabilities and Security Researches

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, 77b9452b-41f3-4ba4-a84a-e49df0113f92

Published on
-
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.40 Form Maker by 10Web &lt; 1.13.40 - Authenticated Reflected XSS The &#039;Form Maker by 10Web&#039; WordPress plugin is vulnerable to XSS in the &#039;blocked_ips_fm&#039; page. A logged-in site administrator who follows a crafted link will trigger arbitrary JavaScript code to be run in their browser in the context of their privileged account on the WordPress site.
Affected versions
max 1.13.40.
Status
vulnerable