CVE-2024-12112
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Jan 8, 2025
CWE ID 79
Summary
CVE-2024-12112: The Easy Form Builder plugin for WordPress, used for creating contact forms, survey forms, payment forms, and custom forms, is found to have a Stored Cross-Site Scripting (XSS) vulnerability. This issue exists in the 'add_form_Emsfb' AJAX action, which lacks proper input sanitization, output escaping, and authorization checks on the 'name' parameter. Consequently, authenticated attackers with Subscriber-level access or higher can inject arbitrary web scripts that will execute whenever a user accesses an affected page.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.