WordPress 插件 Forminator Forms – Contact Form, Payment Form & Custom Form Builder(表单构建器)在 1.57.2 及更早的所有版本中,由于输入净化不足和输出转义不当,存在通过富文本(Rich-Text)文本域字段引发的存储型跨站脚本攻击(Stored XSS)漏洞。 该漏洞允许未经身份验证的攻击者在页面中注入任意 Web 脚本,这些脚本将在用户访问被注入的页面时执行。成功利用该漏洞需要管理员在 Forminator 条目(Entries)
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | ≤ 1.57.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 0 ~ 1.57.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet