Stored Cross-Site Scripting Vulnerability in Tripetto Plugin for WordPress
CVE-2024-13497
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 March 2025
What is CVE-2024-13497?
The Tripetto plugin for WordPress, a popular form builder used for contact forms, surveys, and quizzes, is exposed to a Stored Cross-Site Scripting vulnerability through attachment uploads. This issue arises from inadequate input sanitization and output escaping within all versions up to and including 8.0.9. As a result, unauthenticated attackers can exploit this vulnerability to inject malicious web scripts into the pages hosting the uploaded files. This exploitation can lead to harmful scripts executing in the context of the user's session, potentially compromising the security of the site and its users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress form builder plugin for contact forms, surveys and quizzes β Tripetto * <= 8.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved