Lucene search

K
wpvulndbWpvulndbWPVDB-ID:5A10E929-4A57-431E-856F-5C5E81E42EC8
HistoryMay 22, 2023 - 12:00 a.m.

Contact Form Entries < 1.3.1 - Contributor+ Stored XSS

2023-05-2200:00:00
wpscan.com
7
plugin
sanitization
contributor
web scripts

EPSS

0.001

Percentile

17.5%

The plugin does not sanitize and escape the vx-entries shortcode attributes before using them, which could allow a logged in user with roles as low as contributor to inject arbitrary web scripts into posts or pages.

EPSS

0.001

Percentile

17.5%

Related for WPVDB-ID:5A10E929-4A57-431E-856F-5C5E81E42EC8