First published: Thu Oct 17 2024(Updated: )
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Calculated Fields Form | <=5.2.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-9940 is considered high due to its potential for HTML Injection vulnerabilities.
To fix CVE-2024-9940, update the Calculated Fields Form plugin to the latest version beyond 5.2.45.
All users of the Calculated Fields Form plugin for WordPress up to version 5.2.45 are affected by CVE-2024-9940.
CVE-2024-9940 is an HTML Injection vulnerability allowing attackers to inject arbitrary HTML elements.
Yes, attackers can exploit CVE-2024-9940 without authentication, making it a significant risk.