CVE-2024-12038
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-12038 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Post Form – Registration Form – Profile Form plugin for WordPress. Versions up to 2.8.15 of this plugin are impacted, allowing authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts will execute whenever a user accesses an injected page, posing a serious threat to website security. The vulnerability stems from insufficient input sanitization and output escaping of user-supplied attributes in the plugin's 'buddyforms_nav' shortcode.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.