CVE-2024-23522: WordPress Formidable Forms plugin <= 6.7 - Content Injection vulnerability
Published May 17, 2024
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.
Affected Software
3 affected components
Strategy11 Formidable Forms Wordpress<6.7.1
Strategy11 Formidable Forms>n/a, <=6.7
WordPress Formidable Forms<=6.7
Remediation
Information
Update to 6.7.1 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:47 AM
Data Sourced
via MITRE·08:47 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Aug 9, 57065
Event
via NVD·03:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-23522?
CVE-2024-23522 is a medium-severity vulnerability that allows for code injection due to improper neutralization of script-related HTML tags.
2
How do I fix CVE-2024-23522?
To fix CVE-2024-23522, upgrade Formidable Forms to a version later than 6.7 to ensure the patch is applied.
3
Which versions of Formidable Forms are affected by CVE-2024-23522?
CVE-2024-23522 affects Formidable Forms from version n/a through 6.7.
4
What type of vulnerability is CVE-2024-23522?
CVE-2024-23522 is classified as a Basic Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2024-23522 be exploited by external attackers?
Yes, CVE-2024-23522 can be exploited by external attackers to execute malicious scripts on affected sites.