The NEX-Forms WordPress plugin through 7.9.4 does not...
Moderate severity
Unreviewed
Published
Dec 14, 2021
to the GitHub Advisory Database
•
Updated Mar 26, 2023
Description
Published by the National Vulnerability Database
Dec 13, 2021
Published to the GitHub Advisory Database
Dec 14, 2021
Last updated
Mar 26, 2023
The NEX-Forms WordPress plugin through 7.9.4 does not escape some of its settings and form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
References