CVE-2024-8542: Everest Forms < 3.0.3.1 - Admin+ Stored XSS
The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8542?
CVE-2024-8542 is classified as a high severity vulnerability due to its potential for allowing stored Cross-Site Scripting attacks.
How do I fix CVE-2024-8542?
To fix CVE-2024-8542, update the Everest Forms plugin to version 3.0.3.1 or higher immediately.
Who is affected by CVE-2024-8542?
CVE-2024-8542 affects users and administrators of the Everest Forms plugin in WordPress versions before 3.0.3.1.
What type of vulnerability is CVE-2024-8542?
CVE-2024-8542 is a Stored Cross-Site Scripting (XSS) vulnerability.
What could happen if CVE-2024-8542 is exploited?
If exploited, CVE-2024-8542 could allow attackers to execute arbitrary JavaScript code in the context of a user's browser.