Lucene search

K
wpvulndbAsif Nawaz MinhasWPVDB-ID:75305EA8-730B-4CAF-A3C6-CB94ADEE683C
HistoryOct 06, 2021 - 12:00 a.m.

Formidable Form Builder < 5.0.07 - Admin+ Stored Cross-Site Scripting

2021-10-0600:00:00
Asif Nawaz Minhas
wpscan.com
12

0.001 Low

EPSS

Percentile

21.6%

The plugin does not sanitise and escape its Form’s Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PoC

Create/edit a form, add the following payload to a Field Label: The XSS will be triggered when viewing/previewing the Form

CPENameOperatorVersion
formidablelt5.0.07

0.001 Low

EPSS

Percentile

21.6%

Related for WPVDB-ID:75305EA8-730B-4CAF-A3C6-CB94ADEE683C