Reflected XSS Vulnerability in Everest Forms WordPress Plugin Before 3.1.1
The Everest Forms WordPress plugin has a Cross-Site Scripting (XSS) vulnerability in all versions up to and including 3.1.1. The issue exists in the 'form_id' parameter because of weak input sanitization and output escaping. This allows unauthenticated attackers to inject malicious web scripts into pages. These scripts can execute if a user is tricked into clicking a specially crafted link, potentially compromising their browsing session or website interactions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wpeverest everest forms – contact form, quiz, survey, newsletter & payment form builder for wordpress |
||
wpeverest everest forms |