Vulnerabilities > Incsub > Forminator > 1.6.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-11-23 CVE-2021-24700 Unspecified vulnerability in Incsub Forminator
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
network
low complexity
incsub
4.8