The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-07-31T09:37:34.911Z

Updated: 2024-08-02T06:48:07.875Z

Reserved: 2023-06-06T21:02:25.697Z

Link: CVE-2023-3134

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-31T10:15:10.500

Modified: 2023-11-07T04:17:58.303

Link: CVE-2023-3134

cve-icon Redhat

No data.