Stored Cross-Site Scripting Vulnerability in WPForms WordPress Plugin
CVE-2024-11223
Key Information:
Badges
Summary
The WPForms WordPress plugin, prior to version 1.9.2.3, contains a vulnerability that results from inadequate sanitization and escaping of certain settings. This oversight may empower highly privileged users, including administrators, to execute stored cross-site scripting (XSS) attacks even when the unfiltered_html capability is restricted, such as in multisite environments. Threat actors could exploit this vulnerability to inject malicious scripts, potentially compromising the integrity of user data and the security of the entire website.
Affected Version(s)
WPForms 0 < 1.9.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved