Stored cross-site scripting in Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin

Uncategorized

Exploit availability: No Description. CWE-79 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of….