CVE-2024-13603: Wise Forms <= 1.2.0 - Unauthenticated Stored XSS
Published Feb 17, 2025
·Updated
The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.
Affected Software
2 affected components
Wise Forms WordPress plugin<=1.2.0
Kainex Wise Forms Wordpress<=1.2.0
Event History
Feb 17, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-13603?
CVE-2024-13603 has a high severity due to the potential for stored Cross-Site Scripting attacks.
2
How do I fix CVE-2024-13603?
To fix CVE-2024-13603, update the Wise Forms WordPress plugin to a version later than 1.2.0.
3
Who is affected by CVE-2024-13603?
The vulnerability affects all users of the Wise Forms WordPress plugin version 1.2.0 and below.
4
What type of attack does CVE-2024-13603 enable?
CVE-2024-13603 enables unauthenticated users to perform Stored Cross-Site Scripting (XSS) attacks.
5
Is there a workaround for CVE-2024-13603?
Currently, the only effective workaround for CVE-2024-13603 is to disable the plugin until it is updated.