QID 730782
Date Published: 2023-04-10
QID 730782: WordPress Plugin Zoho Forms Stored Cross-Site Scripting (XSS) Vulnerability
Zoho Forms WordPress plugin create beautiful forms for your website in minutes.
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Versions:
Zoho Forms WordPress plugin versions prior to 3.0.1
QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Zoho Forms plugin.
Successful exploitation of this vulnerability may allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Zoho Forms Plugin Release Notes -
wordpress.org/plugins/zoho-forms/#developers
CVEs related to QID 730782
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho Forms Plugin Release Notes |
|