Filtered by vendor Themehunk Subscriptions
Filtered by product Contact Form \& Lead Form Elementor Builder Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-23180 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2024-11-21 4.3 Medium
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
CVE-2022-23179 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2024-11-21 4.8 Medium
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-24967 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2024-11-21 6.1 Medium
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads