CVE-2021-24967
27.12.2021, 11:15
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads
Vendor | Product | Version |
---|---|---|
themehunk | contact_form_\&_lead_form_elementor_builder | 𝑥 < 1.6.4 |
𝑥
= Vulnerable software versions