4.8
CVSSv3

CVE-2018-7747

Published: 20/04/2018 Updated: 17/07/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin prior to 1.6.0-rc.1 for WordPress allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.

Vulnerable Product Search on Vulmon Subscribe to Product

calderalabs caldera forms

Exploits

# Exploit Title: CalderaForms 1591 - multiple XSS # Date: 02-03-2018 # Exploit Author: Federico Scalco # fscalco at mentat dot is # @mindpr00f # Vendor Homepage: calderaformscom/ # Software Link: wordpressorg/plugins/caldera-forms/ # Vulnerable App: githubcom/CalderaWP/Caldera-Forms/archive/1591zip # Version: ...
WordPress Caldera Forms plugin version 1591 suffers from a cross site scripting vulnerability ...

Github Repositories

CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial

CVE-2018-7747 CalderaForms 1591 XSS (WordPress plugin) - tutorial CalderaForm è un plugin per WordPress che permette di creare facilmente dei form tramite drag and drop Durante una recente attività mi è capitato di testare alcuni portali, uno dei quali ospitava proprio un form di contatti creato tramite questo plugin La configurazione personalizzata d