[Japanese] | |
JVNDB-2024-000097 | |
WordPress Plugin "Forminator" vulnerable to cross-site scripting | |
Overview | |
WordPress Plugin "Forminator" provided by WPMU DEV assists building web forms. When accessing the page including the web form created with Forminator, some information from the URL may be embedded to the web form. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 6.1 (Medium) [IPA Score]
| |
Affected Products | |
| |
WPMU DEV | |
| |
Impact | |
When you follow a crafted URL and access the webpage having the web form created with Forminator, an arbitrary script may be executed on your web browser. | |
Solution | |
[Update the plugin and rebuild the web forms] | |
Vendor Information | |
WPMU DEV | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/09/09 |
Date First Published | 2024/09/09 |
Date Last Updated | 2024/09/09 |