Sploitus

CVE-2023-3134

1 known exploit for CVE-2023-3134

The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.

Affected products
Forminator
Incsub Forminator
< 1.24.4
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
4.1% (90th percentile)
NVD status
Modified
Published
2023-07-31
CVE-2023-3134 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-3134

Proof-of-concept code and exploit modules indexed by Sploitus