CVE-2024-13381: Calculated Fields Form < 5.2.62 - Admin+ Stored XSS
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13381?
The severity of CVE-2024-13381 is classified as high due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13381?
To fix CVE-2024-13381, update the Calculated Fields Form plugin to version 5.2.62 or later.
Who is affected by CVE-2024-13381?
CVE-2024-13381 affects users of the Calculated Fields Form WordPress plugin prior to version 5.2.62.
What kind of attack can CVE-2024-13381 facilitate?
CVE-2024-13381 can facilitate Stored Cross-Site Scripting attacks due to improper sanitization and escaping of settings.
Are admin users vulnerable to CVE-2024-13381?
Yes, high privilege users such as admin can be exploited through CVE-2024-13381 despite having the unfiltered_html capability disallowed.