Security Advisory

CVE-2023-3134

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-07-31 09:37:34
Last updated 2024-08-02 06:48:07
Assigner WPScan
State PUBLISHED

Description

The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.