WordPress · Drag & Drop Builder · CVE-2022-1569
**Name of the Vulnerable Software and Affected Versions**
The Drag & Drop Builder WordPress plugin versions prior to 1.4.9.4
**Description**
The issue is related to the lack of sanitization and escaping of some form fields in the plugin, which could allow high privilege users, such as admins, to perform Cross-Site Scripting attacks when unfiltered html is disallowed.
**Recommendations**
For versions prior to 1.4.9.4, update to version 1.4.9.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's form fields to minimize the risk of exploitation.