🛡️ TSEcurity Gatekeeper
URL VERIFIZIERT

Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High

🔒 https://infosecwriteups.com
«TL;DR: Any anonymous visitor can POST a JavaScript payload to NEX-Forms’ form submission endpoint. The plugin stores it unsanitized in the database. When any admin opens the Entries panel, the payload executes — silently...»
Automatische Weiterleitung... 1.5s
Link in Zwischenablage kopiert!