CVE-2022-2395 Information
Aug 09, 2022
cve
Description
The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Reference
https://wpscan.com/vulnerability/5e442dd9-a49d-4a8e-959b-199a8689da4b
Share on: