CVE-2022-2116
EUVD-2022-3440215.08.2022, 11:20
The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| webacetechs | contact_form_db_-_elementor | 𝑥 < 1.8.0 |
𝑥
= Vulnerable software versions