CVE-2017-18559: Cformsii Project Cformsii
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
Affected products
- Cformsii Project Cformsii: before 14.13.3 (fixed in 14.13.3)
Published 2019-08-21. Last modified 2026-06-17.