CVE-2024-2112: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including user signatures.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2112?
CVE-2024-2112 is classified as a Sensitive Information Exposure vulnerability.
How do I fix CVE-2024-2112?
To fix CVE-2024-2112, update the Form Maker plugin to version 1.15.23 or later.
Who is affected by CVE-2024-2112?
All users of the Form Maker by 10Web plugin up to and including version 1.15.22 are affected by CVE-2024-2112.
What data is exposed in CVE-2024-2112?
CVE-2024-2112 allows unauthenticated attackers to extract sensitive information via the signature functionality.
Is CVE-2024-2112 present in previous versions of the plugin?
Yes, CVE-2024-2112 affects all versions of the Form Maker plugin up to and including 1.15.22.