CVE-2024-11758

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 11, 2025
CWE ID 79

Summary

CVE-2024-12587 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Contact Form Master WordPress plugin before version 1.0.8. The issue lies in the plugin's failure to sanitize and escape user-supplied data before displaying it on the page. An attacker can exploit this weakness by injecting malicious scripts into the contact form submission, which could potentially gain administrative privileges when the form is viewed by a high-level user. This vulnerability poses a significant security risk to WordPress sites running the affected plugin version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share