CVE-2022-23987

All FrameworksWordPressCWE-79CVE-2022-23987

CVE-2022-23987

State: PUBLISHED · Published: 2022-02-28 · Updated: 2024-08-03 · Assigner: WPScan
Description
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/23xxx/CVE-2022-23987.json