Unrated severityNVD Advisory· Published Jun 27, 2022· Updated Aug 3, 2024
Form - Contact Form <= 1.2.0 - Admin+ Stored Cross-Site Scripting
CVE-2022-1326
Description
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/f57615d9-a567-4c2a-9f06-2c6b61f56074mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.