Stored XSS Vulnerabilities in Calculated Fields Form for WordPress
CVE-2020-7228
5.4MEDIUM
What is CVE-2020-7228?
The Calculated Fields Form plugin for WordPress is susceptible to multiple stored cross-site scripting (XSS) vulnerabilities found in input forms. These vulnerabilities can be exploited by authenticated users, potentially allowing them to execute arbitrary JavaScript code in the context of other users. This creates security issues that can lead to data leakage or unauthorized actions within the site.