weForms – Easy Drag & Drop Contact Form Builder For WordPress, CVE-2022-2395
- CVE, Research URL
- Home page URL
-
Security reports for weForms – Easy Drag & Drop Contact Form Builder For WordPress
- Published on
- Aug 08, 2022
- Research Description
- The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected versions
-
max 1.6.14.
- Status
-
vulnerable