Input validation vulnerability in Contact Form by FormGet – Best Form Builder Plugin for WordPress 5.5.5

The Contact Form by FormGet plugin for WordPress is vulnerable to a type of attack known as Stored Cross-Site Scripting. This attack can occur when using the ‘formget’ shortcode in versions up to and including 5.5.5, because the plugin does not properly check or escape the content that users enter. This means that someone with contributor-level or higher privileges can inject malicious code into web pages. This code will execute whenever anyone visits the page, potentially causing harm to them or their computer.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.