CVE-2021-24705: NEX-Forms < 8.4.3 - Stored Cross-Site Scripting via CSRF
Published Dec 13, 2021
·Updated
The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attributes. This could allow attackers to make a logged in admin edit arbitrary forms with Cross-Site Scripting payloads in them
Affected Software
1 affected component
Basixonline Nex-forms Wordpress<=7.9.4
Event History
Dec 13, 2021
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24705?
The severity of CVE-2021-24705 is rated as medium with a score of 4.8.
2
How can I mitigate the vulnerability in NEX-Forms WordPress plugin before 8.4.3?
To mitigate CVE-2021-24705, it is recommended to update the NEX-Forms plugin to version 8.4.3 or newer.
3
What can attackers do if they exploit CVE-2021-24705 in the NEX-Forms plugin before 8.4.3?
Attackers could make a logged-in admin edit arbitrary forms with Cross-Site Scripting (XSS) if they exploit CVE-2021-24705.