CVE-2021-36895 – WordPress Tripetto plugin <= 5.1.4 - Unauthenticated Cross-Site Scripting (XSS) vulnerability via SVG image upload
https://notcve.org/view.php?id=CVE-2021-36895
Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) no autenticado en el plugin Tripetto versiones anteriores a 5.1.4 incluyéndola, en WordPress por medio de una carga de imágenes SVG WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto versions below 5.2 are vulnerable to Cross-Site Scripting. This allows unauthenticated attackers to inject JavaScript into the database. • https://patchstack.com/database/vulnerability/tripetto/wordpress-tripetto-plugin-5-1-4-unauthenticated-cross-site-scripting-xss-vulnerability-via-svg-image-upload https://wordpress.org/plugins/tripetto/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •