Caldera Forms WordPress plugin < 1.9.7 contains a reflected cross-site scripting caused by lack of validation and escaping of the cf-api parameter in responses, letting attackers execute arbitrary scripts in victim's browser, exploit requires attacker to craft a malicious request.
id: CVE-2022-0879
info:
name: Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
author: 0x
...