CVE-2024-31857: XSS
Published Apr 23, 2024
·Updated
Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.
Affected Software
2 affected components
Forminator Forminator<1.15.4
Incsub Forminator Wordpress<1.15.4
Event History
Apr 23, 2024
CVE Published
via MITRE·04:46 AM
Data Sourced
via MITRE·04:46 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31857?
The severity of CVE-2024-31857 is considered medium due to the potential for cross-site scripting exploitation.
2
How do I fix CVE-2024-31857?
To fix CVE-2024-31857, upgrade Forminator to version 1.15.4 or later.
3
What type of vulnerability is CVE-2024-31857?
CVE-2024-31857 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2024-31857?
Users of Forminator version prior to 1.15.4 are affected by CVE-2024-31857.
5
What can an attacker do if CVE-2024-31857 is exploited?
If exploited, an attacker can obtain user information and alter page contents in the user's web browser.