CVE-2024-11223
4.7MEDIUMThe WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even
Published: 12/26/2024Updated: 5/8/2025
Description
The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AI AnalysisPowered by AI
Affected Products
wpformswpforms
References
- https://wpscan.com/vulnerability/82989909-9745-4c9a-abc7-c1adf8c2b047/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/82989909-9745-4c9a-abc7-c1adf8c2b047/ExploitThird Party Advisory