Known CVE
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
Caldera Forms WordPress plugin < 1.9.7 contains a reflected cross-site scripting caused by lack of validation and escaping of the cf-api parameter in responses, letting attackers execute arbitrary scripts in victim's browser, exploit requires attacker to craft a malicious request.
CVE-2022-0879
Medium2022CVSS 6.1CWE-79
wpscan · cve2022 · wordpress · xss · caldera-forms · reflected · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website