CVE-2024-47633: WordPress Zoho forms plugin <= 4.0 - Cross Site Scripting (XSS) vulnerability
Published Oct 5, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Zoho Forms zoho-forms allows Stored XSS.This issue affects Zoho Forms: from n/a through <= 4.0.
Affected Software
1 affected component
Zoho Zoho Forms WordPress plugin<=4.0
Remediation
Information
Update to 4.0.1 or a higher version.
Event History
Oct 5, 2024
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47633?
CVE-2024-47633 is considered a medium severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-47633?
To fix CVE-2024-47633, update Zoho Forms to the latest version beyond 4.0 or apply available patches.
3
What type of vulnerability is CVE-2024-47633?
CVE-2024-47633 is an improper neutralization of input during web page generation vulnerability, specifically a stored XSS issue.
4
Which versions of Zoho Forms are affected by CVE-2024-47633?
CVE-2024-47633 affects Zoho Forms from n/a up to version 4.0.
5
Can the WordPress Zoho Forms Plugin be affected by CVE-2024-47633?
Yes, the WordPress Zoho Forms Plugin is affected by CVE-2024-47633 if it is version 4.0 or lower.