Description
WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Milad karimi
References
www.exploit-db.com/exploits/50734 (ExploitDB-50734)
wordpress.org/plugins/contact-forms-builder/ (Product Reference)
www.vulncheck.com/...s-site-scripting-via-code-generator-php (VulnCheck Advisory: WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php)