Record summary

CVE-2018-14430 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC.

Description

The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2018-14430Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 1.3 KiB

GitHub

PoC details

References

3