Vulnerability Database
API
Submit a vulnerability
Menu
API
Submit a vulnerability
Virtual patches available
See all vulnerabilities
WordPress Drag & Drop Builder plugin <= 1.4.9.3 - Stored Cross-Site Scripting (XSS) vulnerability
pie-forms-for-wp
Software
Drag & Drop Builder
Vulnerable Versions
<= 1.4.9.3
Fixed in version
1.4.9.4
CVE
CVE-2022-1569
References
CVE-2022-1569
Vulnerability details
Plugin changelog
Credits
Hitesh Kumar
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Disclosure Date
2022-05-12
CVSS 3.0 score
4.8
Medium
Requires high role user authentication like admin.
Plugin does not exist, is not supported or discontinued.
Are your websites subject to this vulnerability?
Patch now
View vulnerabilities for this software
Details
Stored Cross-Site Scripting (XSS) vulnerability was discovered by Hitesh Kumar in WordPress Drag & Drop Builder plugin (versions <= 1.4.9.3).
Solution
Update the WordPress Drag & Drop Builder plugin to the latest available version (at least 1.4.9.4).
Found a vulnerability that puts your sites at risk?
Patches available at Patchstack
Found a vulnerability? Help us secure the web and join our community of ethical hackers.
Report a Vulnerability
Are you the developer of this software? Hire our researchers for a thorough security audit.
Learn more
Solutions
Pricing
Articles
Resources
Login
Try Free
Menu
Solutions
Pricing
Articles
Resources
Login
Try Free