PT-2024-33149 · WordPress · Fs Product Inquiry

Bob Matyas

·

Published

2024-06-03

·

Updated

2025-05-06

·

CVE-2024-4857

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FS Product Inquiry WordPress plugin versions 1.1.1 and earlier
Description The issue allows unauthenticated users to perform Stored Cross-Site Scripting attacks due to the plugin not sanitizing and escaping some form submissions.
Recommendations For FS Product Inquiry WordPress plugin versions 1.1.1 and earlier, update to a version that addresses the issue, as the current version does not properly sanitize form submissions, allowing for potential Stored Cross-Site Scripting attacks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-4857

Affected Products

Fs Product Inquiry