Stored Cross-Site Scripting Vulnerability in Tripetto Plugin for WordPress
CVE-2024-13497

6.1MEDIUM

What is CVE-2024-13497?

The Tripetto plugin for WordPress, a popular form builder used for contact forms, surveys, and quizzes, is exposed to a Stored Cross-Site Scripting vulnerability through attachment uploads. This issue arises from inadequate input sanitization and output escaping within all versions up to and including 8.0.9. As a result, unauthenticated attackers can exploit this vulnerability to inject malicious web scripts into the pages hosting the uploaded files. This exploitation can lead to harmful scripts executing in the context of the user's session, potentially compromising the security of the site and its users.

Affected Version(s)

WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto * <= 8.0.9

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.