CVE-2024-13605: Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13605?
CVE-2024-13605 is rated as a moderate severity vulnerability due to the potential for stored Cross-Site Scripting attacks.
What versions of the 10Web Form Maker plugin are affected by CVE-2024-13605?
CVE-2024-13605 affects versions of the 10Web Form Maker plugin prior to 1.15.33.
How do I mitigate CVE-2024-13605?
To mitigate CVE-2024-13605, update the 10Web Form Maker plugin to version 1.15.33 or later.
What kind of attack can CVE-2024-13605 facilitate?
CVE-2024-13605 can facilitate stored Cross-Site Scripting attacks by allowing high privilege users to execute malicious scripts.
Who can exploit CVE-2024-13605?
CVE-2024-13605 can potentially be exploited by users with high privilege, such as administrators, on a WordPress site.