CVE-2021-24718
Description
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CWE
- CWE-79 — CWE-79 Cross-site Scripting (XSS)
Affected
- Unknown / Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder — v=1.5 <1.5 [affected]
CVSS
- (none)
References
Source
cvelistV5-main/cves/2021/24xxx/CVE-2021-24718.json