CVE-2024-9940: Calculated Fields Form <= 5.2.45 - HTML Injection
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9940?
The severity of CVE-2024-9940 is considered high due to its potential for HTML Injection vulnerabilities.
How do I fix CVE-2024-9940?
To fix CVE-2024-9940, update the Calculated Fields Form plugin to the latest version beyond 5.2.45.
Who is affected by CVE-2024-9940?
All users of the Calculated Fields Form plugin for WordPress up to version 5.2.45 are affected by CVE-2024-9940.
What type of vulnerability is CVE-2024-9940?
CVE-2024-9940 is an HTML Injection vulnerability allowing attackers to inject arbitrary HTML elements.
Can attackers exploit CVE-2024-9940 without authentication?
Yes, attackers can exploit CVE-2024-9940 without authentication, making it a significant risk.