CVE-2024-10475: Lead Form Builder < 1.9.8 - Admin+ Stored XSS
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10475?
CVE-2024-10475 has a high severity rating due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-10475?
To fix CVE-2024-10475, update the Responsive Contact Form Builder & Lead Generation Plugin to version 1.9.8 or later.
Who is affected by CVE-2024-10475?
CVE-2024-10475 affects users of the Responsive Contact Form Builder & Lead Generation Plugin on WordPress prior to version 1.9.8.
What type of attack does CVE-2024-10475 enable?
CVE-2024-10475 enables stored cross-site scripting (XSS) attacks by allowing high privilege users to inject malicious scripts.
Are there any specific user roles that can exploit CVE-2024-10475?
Yes, high privilege users such as administrators can exploit CVE-2024-10475 due to the lack of sanitization in settings.