CVE-2024-6243Cross-site Scripting in Html Forms

Severity
4.8MEDIUMNVD
EPSS
0.2%
top 62.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 22

Description

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-4r8x-26vf-3hx6: The HTML Forms WordPress plugin before 12024-07-22
CVEList
HTML Forms < 1.3.33 - Admin+ Stored XSS2024-07-22
CVE-2024-6243 — Cross-site Scripting in Html Forms | cvebase