CVE-2021-24967

MEDIUM WAF: High
CVSS 6.1 Published: 2021-12-27
CWE-79

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
themehunkcontact_form_\&_lead_form_elementor_builderup to 1.6.4

References

Back to CVE Database