Vulnerabilities (CVE)

Filtered by vendor Themehunk Subscribe
Filtered by product Contact Form \& Lead Form Elementor Builder
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23180 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2024-01-24 N/A 4.3 MEDIUM
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
CVE-2022-23179 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2024-01-23 N/A 4.8 MEDIUM
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-24967 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads