CVE-2024-11272: Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11272?
CVE-2024-11272 has a high severity rating due to the potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2024-11272?
To fix CVE-2024-11272, update the PirateForms Contact Form & SMTP Plugin for WordPress to version 2.6.0 or later.
Who is affected by CVE-2024-11272?
Users of the PirateForms Contact Form & SMTP Plugin for WordPress versions prior to 2.6.0 are affected by CVE-2024-11272.
What type of vulnerability is CVE-2024-11272?
CVE-2024-11272 is a Stored Cross-Site Scripting (XSS) vulnerability.
What exploit methods are possible with CVE-2024-11272?
High privilege users, such as administrators, can exploit CVE-2024-11272 to inject malicious scripts into the Contact Form settings.