ZeroHour

CVE-2023-4950

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p39
Published
()
Modified
Description

The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks

Vendors
funnelforms
Products
funnelforms
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.