WordPress Zingiri Form Builder Plugin Cross Site Scripting Vulnerability


The Zingiri Form Builder plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.


The information has been provided by Charlie Eriksen .


Vulnerable Systems:
 * WordPewss Zingiri Form Builder 1.2.0

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Disclosure Timeline:
Published: October 23 2012

Categories: News