CVE-2024-10504: ARForms Builder < 1.7.1 - Unauthenticated Stored XSS
The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10504?
CVE-2024-10504 has a medium severity level due to its potential for enabling Cross-Site Scripting attacks.
How do I fix CVE-2024-10504?
To fix CVE-2024-10504, update the Contact Form, Survey, Quiz & Popup Form Builder plugin to version 1.7.1 or later.
Who is affected by CVE-2024-10504?
Any WordPress site using the Contact Form, Survey, Quiz & Popup Form Builder plugin before version 1.7.1 is affected by CVE-2024-10504.
What type of vulnerability is CVE-2024-10504?
CVE-2024-10504 is a Cross-Site Scripting (XSS) vulnerability due to inadequate sanitization of input parameters.
Can CVE-2024-10504 be exploited by unauthenticated users?
Yes, CVE-2024-10504 allows unauthenticated users to exploit the vulnerability and perform Cross-Site Scripting attacks.