CVE-2024-7691

Publication date

2024-09-02 06:00:04

Family

WPScan

State

PUBLISHED

Description

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.