CVE-2024-8488: Survey Maker – Customer Satisfaction Questionnaire, Chat Survey, Calculation Form, Payment Forms <= 4.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8488?
CVE-2024-8488 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
Who is affected by CVE-2024-8488?
CVE-2024-8488 affects all versions of the Survey Maker plugin for WordPress up to and including version 4.9.7.
How do I fix CVE-2024-8488?
To fix CVE-2024-8488, update the Survey Maker plugin to the latest version where the vulnerability has been patched.
What type of vulnerability is CVE-2024-8488?
CVE-2024-8488 is a Stored Cross-Site Scripting vulnerability caused by insufficient input sanitization and output escaping.
Can attackers exploit CVE-2024-8488 without authentication?
No, CVE-2024-8488 requires authenticated attackers with administrator-level privileges to exploit the vulnerability.