CVE-2024-13053: Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS via Theme Title
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13053?
CVE-2024-13053 has been classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13053?
To fix CVE-2024-13053, update the Form Maker by 10Web plugin to version 1.15.33 or later, which includes necessary security patches.
Who is affected by CVE-2024-13053?
CVE-2024-13053 affects users of the Form Maker by 10Web WordPress plugin versions prior to 1.15.33.
What type of attack can be executed due to CVE-2024-13053?
CVE-2024-13053 allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks.
What are the consequences of CVE-2024-13053 exploitation?
Exploitation of CVE-2024-13053 can lead to unauthorized actions on behalf of users, potentially compromising sensitive information and functionality.