WordPress 的 Forminator Forms – Contact Form, Payment Form & Custom Form Builder 插件在所有版本中(包括 1.57.0.1 及之前版本)存在一个存储型跨站脚本攻击(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于富文本(Rich-Text)文本区域字段缺乏足够的输入净化和输出转义。这使得未认证的 attackers 能够将任意 Web 脚本注入到页面中,当用户访问该被注入的页面时,脚本即会被执行。利用该漏
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | ≤ 1.57.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 0 ~ 1.57.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet