Pojo Forms <= 1.4.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via form_preview_shortcode
mediumThe The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, and including, 1.4.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it po...
- CVSS:
- 6.3
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.8
- Disclosed:
- Dec 5, 2024