Vulnerabilities > Incsub > Forminator > 1.7.0

DATE CVE VULNERABILITY TITLE RISK
2021-11-23 CVE-2021-24700 Unspecified vulnerability in Incsub Forminator
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
network
low complexity
incsub
4.8