CVE-2024-13605
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Feb 24, 2025
CWE ID 79
Summary
CVE-2024-13605 is a vulnerability affecting the Form Maker plugin by 10Web for WordPress. Before version 1.15.33, the plugin does not properly sanitize and escape certain settings, leaving them vulnerable to Stored Cross-Site Scripting (XSS) attacks. Even when the unfiltered_html capability is disabled, high privilege users such as admins can exploit this vulnerability to inject malicious scripts. This can potentially lead to unauthorized access, data theft, or site defacement. Users are advised to update the plugin to the latest version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share