cleantalk
Vulnerabilities and Security Researches

Contact Form DB – Elementor, CVE-2022-2116

CVE, Research URL

CVE-2022-2116

Published on
Aug 15, 2022
Research Description
The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Affected versions
max 1.8.0.
Status
vulnerable