CVE-2021-24896
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Date published : 2021-12-13
https://wpscan.com/vulnerability/2c469e8b-c761-460b-b31d-9219a43006ff
