CVE-2024-48046: WordPress Contact Form by Supsystic plugin <= 1.7.28 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Stored XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48046?
CVE-2024-48046 is classified as a high-severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2024-48046?
To fix CVE-2024-48046, update the Supsystic Contact Form plugin to the latest version beyond 1.7.28.
What types of attacks can CVE-2024-48046 enable?
CVE-2024-48046 can enable stored cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in users' browsers.
Is CVE-2024-48046 present in all versions of the Supsystic Contact Form plugin?
CVE-2024-48046 affects all versions of the Supsystic Contact Form by Supsystic up to and including version 1.7.28.
Can CVE-2024-48046 impact WordPress sites?
Yes, CVE-2024-48046 can impact WordPress sites using the Supsystic WordPress Contact Form plugin up to version 1.7.28.