Lucene search

K
wpvulndbJrXnmWPVDB-ID:50BE0EBF-FE6D-41E5-8AF9-0D74F33AEB57
HistoryDec 21, 2021 - 12:00 a.m.

Easy Forms for Mailchimp < 6.8.6 - Reflected Cross-Site Scripting

2021-12-2100:00:00
JrXnm
wpscan.com
13
mailchimp
cross-site scripting
reflected
sanitise
field name
field type

EPSS

0.001

Percentile

31.7%

The plugin does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PoC

EPSS

0.001

Percentile

31.7%

Related for WPVDB-ID:50BE0EBF-FE6D-41E5-8AF9-0D74F33AEB57