Lucene search

K
wpvulndbWpvulndbWPVDB-ID:FC780BF4-0B49-48A9-BD4A-EA3F29DE4AB1
HistoryNov 03, 2023 - 12:00 a.m.

iframe forms <= 1.0 - Contributor+ Stored Cross-Site Scripting

2023-11-0300:00:00
wpscan.com
6
security
plugin
iframe
forms
xss
web scripts

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

20.8%

Description The plugin does not properly sanitize and escape the ‘iframe’ shortcode. This leads to the possibility of stored Cross-Site Scripting where arbitrary web scripts can be injected into pages.

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

20.8%

Related for WPVDB-ID:FC780BF4-0B49-48A9-BD4A-EA3F29DE4AB1