CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects WordPress.
CVE
CVE-2021-24526
Severity
MEDIUM
CVSS
5.4
EPSS
1.09%
WordPress
Original NVD Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Related CVEs
Other vulnerabilities affecting the same vendor(s)