CVE Published: 16/10/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: WPScan |
Vendor: Unknown |
Product: Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor Status : PUBLISHED
CVE-2023-4950 Description
The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks