Eklenti güvenlik geçmişi
Forminator Forms güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Forminator Forms – Contact Form, Payment Form & Custom Form Builder eklentisi için 36 açık kaydı bulunuyor; en yenisi 1 Ekim 2026 tarihli. Bunların 14 tanesi kritik veya yüksek önemde, 21 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 1.58.0.
- Toplam kayıt
- 36
- Kritik veya yüksek
- 14
- Oturumsuz istismar
- 21
- Son kayıt
- 1 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.57.2 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen “Forminator Forms – Contact Form, Payment Form & Custom Form Builder” eklentisi, yetersiz girdi temizleme ve çıktı kaçış işlemleri nedeniyle 1.57.2 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde “postdata-1[post-custom]” parametresi aracılığıyla depolanmış siteler arası komut çalıştırma (Stored Cross-Site Scripting) saldırısına açıktır. Bu durum, kimlik doğrulaması yapılmamış saldırganların, bir kullanıcı enjekte edilen sayfaya her eriştiğinde çalışacak şekilde sayfalara rastgele web komut dosyaları enjekte etmesine olanak tanır. Gerekli form gönderim noncesi, kimliği doğrulanmamış kullanıcılar tarafından herkese açık wp_ajax_nopriv_forminator_get_nonce uç noktası aracılığıyla serbestçe elde edilebildiğinden, tam saldırı zinciri herhangi bir kimlik doğrulama veya önceden oluşturulmuş bir hesap gerektirmeden istismar edilebilir.
Türkçe kayıt ve ne yapmalıdepolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.57.2 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen “Forminator Forms – Contact Form, Payment Form & Custom Form Builder” eklentisi, yetersiz girdi temizleme ve çıktı kaçış işlemleri nedeniyle 1.57.2 sürümü dahil olmak üzere tüm sürümlerinde, Zengin Metin (Rich-Text) Textarea Alanı aracılığıyla depolanmış siteler arası komut enjeksiyonu (Stored Cross-Site Scripting) saldırılarına açıktır. Bu durum, kimliği doğrulanmamış saldırganların, bir kullanıcı enjekte edilmiş bir sayfaya her eriştiğinde çalışacak şekilde sayfalara keyfi web komut dosyaları enjekte etmesine olanak tanır. Saldırının başarılı olması için, bir yöneticinin Forminator Girişleri görünümünde depolanmış gönderim girişini açması ve yerleştirilmiş bağlantıyla etkileşime girmesi gerekir; bu noktada WordPress çekirdeğinin `.contextual-help-tabs a` öğesindeki jQuery tabanlı tıklama işleyicisi, varlık kodlaması kaldırılmış href'yi HTML olarak değerlendirir ve saldırganın yükünü, yöneticinin kimlik doğrulaması yapılmış wp-admin oturumunda çalıştırır.
Türkçe kayıt ve ne yapmalıhatalı girdi doğrulama
Etkilenen sürümler: 1.57.2.1 öncesi · Oturum açmadan istismar edilebilir
1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi, bir form gönderiminin hangi meta veri anahtarlarını sağlayabileceğini kısıtlamamakta ve WordPress adresinin kendi kullanımı için ayırdığı anahtarları hariç tutmamaktadır; bu nedenle, yayın içeriğini toplayan halka açık bir formu gönderen kimliği doğrulanmamış ziyaretçiler, gönderdikleri formun oluşturduğu yayına istedikleri meta verileri ekleyebilirler.
güvenlik
Etkilenen sürümler: 1.57.2.1 öncesi · Oturum açmadan istismar edilebilir
1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi, bağlantı adresi yerine istemci tarafından sağlanan yönlendirme başlıklarını tercih etmeden önce, isteğin güvenilir bir proxy'den geldiğini doğrulamamaktadır ve bu değeri hem ziyaretçi başına oy sınırını uygulamak hem de bir girişi kimin gönderdiğini kaydetmek için kullanmaktadır. Bu nedenle, kimlik doğrulaması yapılmamış ziyaretçiler herhangi bir ankette sınırsız oy kullanabilir ve yaptıkları her gönderim için kaydedilecek adresi seçebilirler.
eksik yetki denetimi
Etkilenen sürümler: 1.57.2.1 öncesi · Oturum açmadan istismar edilebilir
1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi, taslak kaydetme bildirimini taslağı oluşturan ziyaretçiye bağlamaz ve hem alıcı adresini hem de mesaja yazılan bağlantıyı istekten alır; böylece kimliği doğrulanmamış ziyaretçiler, sitenin kendi posta yapılandırmasından herhangi bir adrese, sitenin kendi şablonu içinde kendi seçtikleri bir bağlantıyı içeren bir mesaj gönderilmesini sağlayabilir. Gönderimi yetkilendiren jeton, 1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi tarafından anonim çağrı yapan kişiye verilir ve sınırsız olarak tekrar kullanılabilir.
eksik yetki denetimi
Etkilenen sürümler: 1.57.2.1 öncesi
1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi, yönetici ekranlarından birinin oluşturulması sırasında tek seferlik ödeme alanı geçişini çalıştırmadan önce nonce, yetki veya sahiplik kontrolü yapmamaktadır; bu oluşturma işlemi ise oturum açmış herhangi bir kullanıcı için her wp-admin isteğinde gerçekleşmektedir. Bu nedenle, 1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisinde herhangi bir izni olmayan Abone dahil olmak üzere, kimlik doğrulaması yapılmış herhangi bir kullanıcı, sitedeki canlı ödeme formu da dahil olmak üzere herhangi bir formun kaydedilmiş alan yapılandırmasını yeniden yazabilir.
yetki yükseltme
Etkilenen sürümler: 1.57.2.1 öncesi
1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi, bir kayıt formu içe aktarılan bir sınava iç içe yerleştirildiğinde, başka yerlerde uyguladığı rol doğrulamasını uygulamamaktadır; bu durum, sınavları içe aktarabilen bir kullanıcının, formu gönderen herkese yönetici dahil olmak üzere herhangi bir rolü veren, canlı ve herkese açık bir form yayınlamasına olanak sağlamaktadır. Aynı kullanıcı, hem normal form düzenleyicisi hem de normal form içe aktarma yoluyla aynı formu kullanmaya çalışırsa reddedilir.
uzaktan kod çalıştırma
Etkilenen sürümler: 1.57.2.1 öncesi
1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisi, bir XML-RPC isteğinden alınan bir değeri serileştirirken hangi sınıfların örneklendirilebileceğini kısıtlamamaktadır; bu da, form yönetimi iznine sahip kullanıcıların istedikleri bir dosyayı yazmalarına ve keyfi kod çalıştırmalarına olanak tanımaktadır. Bu izin varsayılan olarak bir yöneticiye aittir ve 1.57.2.1 sürümünden önceki Forminator Forms WordPress eklentisinin kendi ayarları aracılığıyla sitenin herhangi bir role vermiş olduğu izinlere de aittir; dolayısıyla bu özelliği kullanan sitelerde, yönetici seviyesinin çok altındaki kullanıcılar da bu sorundan yararlanabilir.
uzaktan kod çalıştırma
Etkilenen sürümler: 1.57.2 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen “The Forminator Forms – Contact Form, Payment Form & Custom Form Builder” eklentisi, 1.57.2 sürümü dahil olmak üzere tüm sürümlerinde keyfi kısa kod çalıştırma güvenlik açığına maruz kalmaktadır. Bu durum, yazılımın kullanıcıların do_shortcode işlevini çalıştırmadan önce bir değeri düzgün bir şekilde doğrulamayan bir eylemi gerçekleştirmesine izin vermesinden kaynaklanmaktadır. Bu da, kimlik doğrulaması yapılmamış saldırganların keyfi kısa kodları çalıştırmasına imkân vermektedir.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.57.0.1 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen “Forminator Forms – Contact Form, Payment Form & Custom Form Builder” eklentisi, yetersiz girdi temizleme ve çıktı kaçış işleme nedeniyle 1.57.0.1 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde, Zengin Metin (Rich-Text) Textarea alanı üzerinden depolanmış siteler arası komut enjeksiyonu (Stored Cross-Site Scripting) saldırılarına karşı savunmasızdır. Bu durum, kimlik doğrulaması yapılmamış saldırganların, bir kullanıcı enjekte edilen sayfaya her eriştiğinde çalıştırılacak rastgele web komut dosyalarını sayfalara enjekte etmesine olanak tanır. Bu güvenlik açığından yararlanılabilmesi için, hedef alınan Textarea alanındaki Zengin Metin düzenleyici seçeneğinin etkinleştirilmiş olması gerekir.
yetki yükseltme
Etkilenen sürümler: 1.57.1 öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.57.0 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is only triggerable on pages hosting a Forminator form configured to use the Stripe Checkout Sessions payment API, which became the default in 1.56.0.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.57.0.2 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because the Save-and-Continue draft submission AJAX endpoint is registered as nopriv, allowing unauthenticated attackers to bypass radio field option-membership validation and persist a crafted payload that, when rendered on the Submissions admin page, is auto-executed via the bundled Inputmask library's data-attribute callback binding.
yetki yükseltme
Etkilenen sürümler: 1.57.0.7 öncesi
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
uzaktan kod çalıştırma
Etkilenen sürümler: 1.57.0.5 öncesi
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
kısıtlamasız dosya yükleme
Etkilenen sürümler: 1.56.1 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.55.0.2 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate sequential integer entry IDs via the 'draft' parameter and read other users' saved draft form data, including names, email addresses, phone numbers, addresses, and free-form message content. This is only exploitable on forms that have the 'Save and Continue' feature enabled.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.56.1 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is possible because Forminator_Core::sanitize_array() skips all filtering for keys prefixed with 'select-', and set_field_data() treats a submitted 'return' member as a trusted internal flag — allowing an unauthenticated attacker to forge and persist a complete upload field record with an arbitrary file_url value without any sanitization or validation.
eksik yetki denetimi
Etkilenen sürümler: 1.53.0 ve öncesi
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check before saving the scheduled export configuration, unlike the parallel listen_for_csv_export() function which correctly verifies user permissions. This makes it possible for authenticated attackers with subscriber-level access to configure a scheduled export job that emails all form submissions to an attacker-controlled email address, resulting in sensitive data exfiltration.
eksik yetki denetimi
Etkilenen sürümler: 1.51.1 ve öncesi
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management actions — including export, delete, clone, delete-entries, publish/draft, and bulk variants — after only a nonce check, without ever verifying that the current user holds the `manage_forminator_modules` capability. The nonce used (`forminator_form_request`) is unconditionally embedded in the global `forminatorData` JavaScript object and localized on every Forminator admin page, including Templates and Reports pages accessible to users who explicitly lack module-management permissions. Because `processRequest()` is invoked during the `admin_menu` action hook — which fires before WordPress enforces page-level capability checks — a user whose Forminator role is restricted to Templates or Reports can craft a valid POST request targeting any published module and successfully trigger the vulnerable actions. This makes it possible for authenticated attackers with subscriber-level access (or any custom low-privilege Forminator role) to export the complete internal configuration of arbitrary forms/polls/quizzes (including notification routing, integration credentials, and conditional logic), delete modules, delete all submissions/votes, clone modules, or bulk-change publish/draft status.
dizin geçişi (path traversal)
Etkilenen sürümler: 1.52.1 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.52.1 via the 'upload-1[file][file_path]' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires a publicly accessible form with a File Upload field where Save and Continue is enabled in that form's Behavior settings and the Save and Continue email notification is configured to attach uploaded files in Email Notifications.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.50.2 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin allows admins to give form management permissions to lower level users, which could make this exploitable by users such as subscribers.
eksik yetki denetimi
Etkilenen sürümler: 1.49.1 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with access to the Forminator dashboard, to export sensitive form submission data including personally identifiable information.
SQL enjeksiyonu
Etkilenen sürümler: 1.45.0 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
PHP nesne enjeksiyonu
Etkilenen sürümler: 1.44.2 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function. This makes it possible for unauthenticated attackers to inject a PHP Object through a PHAR file. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Deserialization occurs when the form submission is deleted, whether by an Administrator or via auto-deletion determined by plugin settings.
rastgele dosya silme
Etkilenen sürümler: 1.44.2 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including, 1.44.2. This makes it possible for unauthenticated attackers to include arbitrary file paths in a form submission. The file will be deleted when the form submission is deleted, whether by an Administrator or via auto-deletion determined by plugin settings. This can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.44.1 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.42.0 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
güvenlik
Etkilenen sürümler: 1.42.0 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.39.2 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template data in all versions up to, and including, 1.39.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.38.3 öncesi
The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.38.2 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.36.0 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submit_quizzes() function due to missing validation on the 'entry_id' user controlled key. This makes it possible for unauthenticated attackers to modify other user's quiz submissions.
eksik yetki denetimi
Etkilenen sürümler: 1.35.1 ve öncesi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 1.35.1 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the custom form 'create_module' function. This makes it possible for unauthenticated attackers to create draft forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 1.35.1 ve öncesi · Oturum açmadan istismar edilebilir
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the quiz 'create_module' function. This makes it possible for unauthenticated attackers to create draft quizzes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Türkçe açıklamalar makine çevirisidir; bağlayıcı metin NVD’deki İngilizce kayıttır. Veri 8 Ekim 2026 itibarıyla.