PT-2024-38513 · WordPress · Flaming Forms

Bob Matyas

·

Published

2024-09-01

·

Updated

2024-10-04

·

CVE-2024-7691

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Flaming Forms WordPress plugin versions 1.0.1 and earlier
Description The issue is related to the Flaming Forms WordPress plugin, which does not properly sanitise and escape certain parameters. This could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.
Recommendations For versions 1.0.1 and earlier, update to a version that properly sanitises and escapes parameters to prevent Cross-Site Scripting attacks. As a temporary workaround, consider restricting access to the plugin's functionality to minimise the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7691

Affected Products

Flaming Forms