cleantalk
Vulnerabilities and Security Researches

Contact Form by WPForms – Drag & Drop Form Builder for WordPress, CVE-2020-10385

CVE, Research URL

CVE-2020-10385

Published on
Mar 24, 2020
Research Description
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
Affected versions
Min -, max 1.4.8.
Status
vulnerable