CVE-2024-13382: Calculated Fields Form < 5.2.64 - Admin+ Stored XSS
Published May 15, 2025
·Updated
The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
2 affected components
Calculated Fields Form Calculated Fields Form<5.2.64
CodePeople Calculated Fields Form Wordpress<=5.2.64
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-13382?
CVE-2024-13382 has a high severity level due to the potential for stored Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-13382?
To fix CVE-2024-13382, update the Calculated Fields Form plugin to version 5.2.64 or later.
3
Who is affected by CVE-2024-13382?
CVE-2024-13382 affects installations of the Calculated Fields Form plugin prior to version 5.2.64.
4
What type of vulnerability is CVE-2024-13382?
CVE-2024-13382 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can low privilege users exploit CVE-2024-13382?
No, CVE-2024-13382 can only be exploited by high privilege users, such as admins.