CVE-2024-6243: HTML Forms < 1.3.33 - Admin+ Stored XSS
The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfilteredhtml capability is disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6243?
The severity of CVE-2024-6243 is rated as high due to its potential for allowing stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-6243?
To fix CVE-2024-6243, update the HTML Forms WordPress plugin to version 1.3.33 or later.
Who is affected by CVE-2024-6243?
CVE-2024-6243 affects high-privilege users, including administrators of the HTML Forms WordPress plugin prior to version 1.3.33.
What types of attacks are possible with CVE-2024-6243?
CVE-2024-6243 allows attackers to perform stored Cross-Site Scripting (XSS) attacks, enabling them to inject malicious scripts.
What versions of the HTML Forms plugin are vulnerable to CVE-2024-6243?
Versions of the HTML Forms WordPress plugin prior to 1.3.33 are vulnerable to CVE-2024-6243.