Sploitus

CVE-2021-24526

1 known exploit for CVE-2021-24526

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

Affected products
The Form Maker
10web Form Maker
< 1.13.60
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
1.1% (63th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-08-16
CVE-2021-24526 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24526

Proof-of-concept code and exploit modules indexed by Sploitus