Lucene search

K
wpvulndbMgthuramoemyintWPVDB-ID:1806FEF3-D774-46E0-AA48-7A101495F4EB
HistoryMay 22, 2024 - 12:00 a.m.

Arforms < 6.4.1 - Reflected XSS

2024-05-2200:00:00
mgthuramoemyint
wpscan.com
1
arforms
plugin
xss
user input
ajax actions

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Description The plugin does not properly escape user-controlled input when it is reflected in some of its AJAX actions.

PoC

https://www.example.com/wp-admin/admin-ajax.php?action=current_modal&amp;position;_modal=

CPENameOperatorVersion
eq6.4.1

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for WPVDB-ID:1806FEF3-D774-46E0-AA48-7A101495F4EB