WordPress · Wise Forms · CVE-2024-13603
**Name of the Vulnerable Software and Affected Versions**
Wise Forms WordPress plugin version 1.2.0
**Description**
The issue allows unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions because the plugin does not sanitise and escape some of its settings.
**Recommendations**
For Wise Forms WordPress plugin version 1.2.0, update to a version that addresses the sanitization and escaping of settings to prevent Stored Cross-Site Scripting attacks.