CVE-2022-23988

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2022-02-28 09:15

Updated : 2022-02-28 13:37


NVD link : CVE-2022-23988

Mitre link : CVE-2022-23988


JSON object : View

Products Affected

No product.

CWE

No CWE.