nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24967 CVE-2021-24967
MEDIUM
Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-24967 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Contact Form & Lead Form Elementor Builder | CVE List | 1.6.4 to < 1.6.4 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24967Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24967Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/4e165122-4746-42de-952e-a3bf51393a74