Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24134
HistoryMar 18, 2021 - 2:57 p.m.

CVE-2021-24134 Constant Contact Forms < 1.8.8 - Multiple Authenticated Stored XSS

2021-03-1814:57:49
CWE-79
WPScan
www.cve.org

0.001 Low

EPSS

Percentile

24.8%

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

CNA Affected

[
  {
    "product": "Constant Contact Forms",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.8.8",
        "status": "affected",
        "version": "1.8.8",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

24.8%

Related for CVELIST:CVE-2021-24134