CVE-2024-10054: Happyforms < 1.26.3 - Admin+ Stored XSS
The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10054?
CVE-2024-10054 is considered a critical vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10054?
To remediate CVE-2024-10054, update the Happyforms plugin to version 1.26.3 or later.
Who is affected by CVE-2024-10054?
CVE-2024-10054 affects installations of the Happyforms plugin prior to version 1.26.3, particularly in WordPress environments.
What type of attack does CVE-2024-10054 facilitate?
CVE-2024-10054 allows high privilege users to perform Stored Cross-Site Scripting attacks due to insufficient sanitization and escaping of settings.
Is CVE-2024-10054 specific to certain user roles?
Yes, CVE-2024-10054 particularly impacts high privilege users, such as administrators, in WordPress multisite setups.