CVE-2024-54223: WordPress ARForms plugin <= 1.7.1 - HTML Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms Form Builder arforms-form-builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through <= 1.7.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54223?
CVE-2024-54223 is a medium severity vulnerability allowing improper neutralization of script-related HTML tags in the ARForms Form Builder.
How do I fix CVE-2024-54223?
To fix CVE-2024-54223, users should update the ARForms Form Builder to the latest version beyond 1.7.1.
What does CVE-2024-54223 affect?
CVE-2024-54223 affects all versions of Repute InfoSystems ARForms Form Builder from n/a up to and including 1.7.1.
What type of vulnerability is CVE-2024-54223?
CVE-2024-54223 is classified as a Basic Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-54223 be exploited by an attacker?
Yes, CVE-2024-54223 can be exploited by an attacker to inject malicious code through the affected Contact Form.