CVE-2014-10377: Cformsii Project Cformsii
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
Affected products
- Cformsii Project Cformsii: before 13.2 (fixed in 13.2)
Published 2019-08-21. Last modified 2026-06-17.