Vulnerability Details: Reflected Cross-Site Scripting (XSS) in Smart Forms
The changelog for the latest version of the plugin Smart FormsĀ is “Security fix.” Looking at the changes made in that we found that one set of changes was labeled as “escaping get and post requests“, but we found that one of the changes involved a reflected cross-site scripting (XSS) vulnerability occurring on two lines in a row in the plugin, which was not actually escaped.
...
This post provides insights on a vulnerability in the WordPress plugin Smart Forms not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.
If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.
For existing customers, please log in to your account to view the rest of the contents of the post.
Plugin Security Scorecard Grade for Smart Forms
Checked on August 23, 2024B