mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 23:28:04 +02:00
924 B
924 B
CVE-2021-24967
Description
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads
POC
Reference
- https://wpscan.com/vulnerability/4e165122-4746-42de-952e-a3bf51393a74
- https://wpscan.com/vulnerability/4e165122-4746-42de-952e-a3bf51393a74
Github
No PoCs found on GitHub currently.