CVE-2024-13605

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 79

Summary

CVE-2024-13605 is a vulnerability affecting the Form Maker plugin by 10Web for WordPress. Before version 1.15.33, the plugin does not properly sanitize and escape certain settings, leaving them vulnerable to Stored Cross-Site Scripting (XSS) attacks. Even when the unfiltered_html capability is disabled, high privilege users such as admins can exploit this vulnerability to inject malicious scripts. This can potentially lead to unauthorized access, data theft, or site defacement. Users are advised to update the plugin to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share