The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wpvulndb.com/vulnerabilities/9186 | exploit third party advisory patch |
https://ansawaf.blogspot.com/2018/10/cve-2018-14846-multiple-stored-xss-in.html | third party advisory exploit |
https://cwatch.comodo.com/blog/website-security/vulnerability-found-in-multiple-stored-xss-form-in-wordpress-version-1-2-5/ | exploit third party advisory patch |