CVE-2021-24505 – Forms < 1.12.3 - Authenticated Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24505
The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field. El plugin Forms WordPress versiones anteriores a 1.12.3, no saneaba sus campos input, conllevando a problemas de tipo Cross-Site scripting Almacenado. El plugin era susceptible a una vulnerabilidad de tipo Cross-Site Scripting (XSS) Almacenado y Autenticado dentro del campo "Add new" Forms • https://wpscan.com/vulnerability/550e08ac-4c3a-4e22-8e98-bc5bfc020ca9 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •