CVE-2021-24526
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not esca
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.
MEDIUM · CVSS 5.4
EPSS 0.00368
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0