Lucene search

K
wpexploitAsif Nawaz MinhasWPEX-ID:75305EA8-730B-4CAF-A3C6-CB94ADEE683C
HistoryOct 06, 2021 - 12:00 a.m.

Formidable Form Builder < 5.0.07 - Admin+ Stored Cross-Site Scripting

2021-10-0600:00:00
Asif Nawaz Minhas
141
formidable form builder
cross-site scripting
admin+
stored exploit

EPSS

0.001

Percentile

21.4%

The plugin does not sanitise and escape its Form’s Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Create/edit a form, add the following payload to a Field Label: <script>alert(/XSS/)</script>

The XSS will be triggered when viewing/previewing the Form

EPSS

0.001

Percentile

21.4%

Related for WPEX-ID:75305EA8-730B-4CAF-A3C6-CB94ADEE683C