CVE-2024-45625: XSS
Published Sep 9, 2024
·Updated
Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.
Affected Software
1 affected component
Incsub Forminator Wordpress<1.34.1
Remediation
Event History
Sep 9, 2024
CVE Published
via MITRE·04:44 AM
Data Sourced
via MITRE·04:44 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45625?
CVE-2024-45625 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2024-45625?
To fix CVE-2024-45625, update the Forminator plugin to version 1.34.1 or later.
3
What versions of Forminator are affected by CVE-2024-45625?
CVE-2024-45625 affects all Forminator versions prior to 1.34.1.
4
What type of vulnerability is CVE-2024-45625?
CVE-2024-45625 is a cross-site scripting (XSS) vulnerability.
5
What can happen if CVE-2024-45625 is exploited?
If exploited, CVE-2024-45625 can allow an attacker to execute arbitrary scripts in the user's web browser.