Beta

Report

Perfect Survey <= 1.5.2 is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability

Unauthenticated
Published
2021-10-04

The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue

CVSS

Score:6.1

Severity:Medium

Version: 1.5.2

The plugin vendor has not patched this vulnerability at the moment.