CVE Database
/

CVE-2022-0402

Back to search

CVE-2022-0402

Published: Jan 16, 2024

Modified: Jun 20, 2025

PUBLISHED

Description

The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting. The action is also lacking CSRF, making the attack easier to perform against any user.

VendorProductVersions

Unknown

Super Forms - Drag & Drop Form Builder

affected
0 - < 6.0.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now