CVE-2024-43220: WordPress Form Maker by 10Web plugin <= 1.15.26 - Reflected Cross Site Scripting (XSS) vulnerability
Published Aug 12, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.
Affected Software
3 affected components
10web Form Maker<=1.15.26
10web WordPress Form Maker plugin<=1.15.26
10web Form Maker Wordpress<1.15.27
Event History
Aug 12, 2024
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43220?
CVE-2024-43220 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-43220?
To fix CVE-2024-43220, upgrade the 10Web Form Maker plugin to version 1.15.27 or later.
3
What versions of 10Web Form Maker are affected by CVE-2024-43220?
CVE-2024-43220 affects all versions of 10Web Form Maker up to and including version 1.15.26.
4
What is reflected XSS as related to CVE-2024-43220?
Reflected XSS in CVE-2024-43220 allows attackers to inject malicious scripts into web pages viewed by users.
5
Who is the vendor for CVE-2024-43220?
The vendor for CVE-2024-43220 is 10Web, responsible for developing the Form Maker plugin.