CVE-2021-24526: Form Maker < 1.13.60 - Authenticated Stored XSS
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Other sources
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24526?
CVE-2021-24526 is a vulnerability in the Form Maker by 10Web WordPress plugin that allows an authenticated user to execute arbitrary JavaScript code.
How does CVE-2021-24526 occur?
CVE-2021-24526 occurs because the plugin does not properly sanitize the Form Title before displaying it in an attribute, allowing an attacker to inject malicious code.
What is the severity of CVE-2021-24526?
CVE-2021-24526 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2021-24526?
To fix CVE-2021-24526, you should update the Form Maker by 10Web plugin to version 1.13.60 or higher.
Is there any additional information about CVE-2021-24526?
Yes, you can find more information about CVE-2021-24526 at the following reference: https://wpscan.com/vulnerability/17287d8a-ba27-42dc-9370-a931ef404995