CVE-2024-4061: Survey Maker < 4.2.9 - Admin+ Stored XSS via Plugin Settings
The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4061?
CVE-2024-4061 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-4061?
To fix CVE-2024-4061, update the Survey Maker WordPress plugin to version 4.2.9 or later.
Who is affected by CVE-2024-4061?
CVE-2024-4061 affects users of the Survey Maker WordPress plugin prior to version 4.2.9.
What type of attacks can CVE-2024-4061 enable?
CVE-2024-4061 can enable Stored Cross-Site Scripting attacks for high privilege users, such as admins.
What settings are improperly handled in CVE-2024-4061?
CVE-2024-4061 involves the improper sanitization and escaping of some settings within the Survey Maker plugin.