Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data
highThe Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unaut...
- CVSS:
- 7.2
- Affected:
- up to 1.0.15
- Fixed in:
- 1.0.16
- Disclosed:
- Jun 5, 2026