Cross-Site Scripting Vulnerabilities in NEX-Forms Lite by WordPress
CVE-2014-7151
6.1MEDIUM
What is CVE-2014-7151?
The NEX-Forms Lite plugin for WordPress contains multiple cross-site scripting vulnerabilities that can be exploited by remote attackers. These vulnerabilities arise from insufficient validation of user input in the form_fields parameter during do_edit or do_insert actions handled through wp-admin/admin-ajax.php. Successful exploitation could allow attackers to inject arbitrary web scripts or HTML into the site's interface, potentially compromising the security and integrity of the website.