CVE-2024-9768: Formidable Forms < 6.14.1 - Admin+ Stored XSS
The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9768?
CVE-2024-9768 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks by users with elevated privileges.
How do I fix CVE-2024-9768?
To fix CVE-2024-9768, update the Formidable Forms WordPress plugin to version 6.14.1 or later.
Who is affected by CVE-2024-9768?
CVE-2024-9768 affects installations of the Formidable Forms WordPress plugin prior to version 6.14.1.
What type of attack is possible through CVE-2024-9768?
CVE-2024-9768 allows high privilege users to perform Stored Cross-Site Scripting (XSS) attacks.
Does CVE-2024-9768 affect multisite installations?
Yes, CVE-2024-9768 can affect multisite installations of WordPress where unfiltered_html capability is disallowed.