Vendor
high
advisory
Stored XSS in WPForms Pro Plugin
2 TTPs 1 CVEWPForms Pro versions up to 2.0.0.2 are vulnerable to unauthenticated Stored Cross-Site Scripting via improper input sanitization in text fields.
WPForms Pro
2t
1c
high
advisory
WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 IOCThe WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.
WPForms Pro plugin for WordPress <= 1.10.1.1 +1
wordpress
rce
arbitrary-file-upload
web-vulnerability
1r
2t
1i
updated