CVE-2024-10560: Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10560?
CVE-2024-10560 is considered a critical vulnerability due to its potential for enabling Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10560?
To fix CVE-2024-10560, update the Form Maker by 10Web plugin to version 1.15.30 or later.
Who is affected by CVE-2024-10560?
CVE-2024-10560 affects users of the Form Maker by 10Web WordPress plugin prior to version 1.15.30.
What types of attacks can CVE-2024-10560 facilitate?
CVE-2024-10560 can facilitate Stored Cross-Site Scripting attacks, particularly against high privilege users such as administrators.
Is it safe to use versions of Form Maker prior to 1.15.30 after CVE-2024-10560?
No, using versions prior to 1.15.30 is unsafe due to the vulnerabilities outlined in CVE-2024-10560.