CVE-2023-4950

Publication date

2023-10-16 19:38:58

Family

WPScan

State

PUBLISHED

Description

The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks