CVE Published: 06/12/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder Status : PUBLISHED
CVE-2021-24718 Description
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed