XSS was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress via the rm_form_id, rm_tr, or form_name parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://Spider-security.co.uk | third party advisory |
https://wordpress.org/plugins/custom-registration-form-builder-with-submission-manager/#developers | release notes |
https://spider-security.co.uk/blog-cve-2020-8436 | third party advisory exploit |