CVE-2024-3637: Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSS
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3637?
CVE-2024-3637 has a high severity rating due to potential Stored Cross-Site Scripting vulnerabilities.
How do I fix CVE-2024-3637?
To fix CVE-2024-3637, update the Responsive Contact Form Builder & Lead Generation Plugin to the latest version available.
Who is affected by CVE-2024-3637?
CVE-2024-3637 affects users of the Responsive Contact Form Builder & Lead Generation Plugin version 1.8.9 and earlier.
What type of attack can exploit CVE-2024-3637?
CVE-2024-3637 can be exploited through Stored Cross-Site Scripting attacks by high privilege users.
Does CVE-2024-3637 affect all WordPress users?
No, CVE-2024-3637 specifically affects WordPress users who have the Responsive Contact Form Builder & Lead Generation Plugin installed.