CVE-2024-11273: Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11273?
CVE-2024-11273 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-11273?
To fix CVE-2024-11273, update the PirateForms Contact Form & SMTP Plugin to version 2.6.0 or later.
Who is affected by CVE-2024-11273?
CVE-2024-11273 affects users of the PirateForms Contact Form & SMTP Plugin for WordPress prior to version 2.6.0.
What kind of attacks can be performed due to CVE-2024-11273?
CVE-2024-11273 can allow high privilege users to perform Stored Cross-Site Scripting attacks.
Does CVE-2024-11273 require specific user permissions to exploit?
Yes, CVE-2024-11273 requires high privilege user permissions, such as admin access, to exploit.