vendor:
wpforms_lite
by:
Milad karimi
8.8
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: wpforms_lite
Affected Version From: 1.7.2008
Affected Version To: 1.7.2008
Patch Exists: NO
Related CWE:
CPE: 2.3:a:wordpress:wpforms_lite:1.7.8
Platforms Tested: Windows 10
2022
WPForms 1.7.8 – Cross-Site Scripting (XSS)
This plugin creates a WPForms from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.