CVE-2024-11273
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
Summary
CVE-2024-11273 is a vulnerability affecting the Contact Form & SMTP Plugin for WordPress by PirateForms. Before version 2.6.0, this plugin failed to sanitize and escape certain settings. This issue permits high privilege users, including admins, to execute Stored Cross-Site Scripting attacks. Even when the unfiltered_html capability is disallowed, as in multisite setups, the vulnerability still poses a threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.