PT-2026-6028 · WordPress · Wordpress+1
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Form Maker plugin for WordPress versions prior to 1.15.36
Description
The Form Maker plugin for WordPress is susceptible to Stored Cross-Site Scripting through hidden field values. Insufficient output escaping when displaying these values in the admin submissions list allows for the execution of arbitrary web scripts. The plugin utilizes
html entity decode() on user-supplied hidden field values without subsequent escaping before output, converting HTML entity-encoded payloads into executable JavaScript. This enables unauthenticated attackers to inject malicious scripts into the admin submissions view, which will execute when an administrator accesses the submissions list.Recommendations
Update the Form Maker plugin to version 1.15.36 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Form Maker
Wordpress