PT-2025-6580 · WordPress · Wise Forms

Cursed

+3

·

Published

2025-02-17

·

Updated

2025-05-14

·

CVE-2024-13603

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wise Forms WordPress plugin version 1.2.0
Description The issue allows unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions because the plugin does not sanitise and escape some of its settings.
Recommendations For Wise Forms WordPress plugin version 1.2.0, update to a version that addresses the sanitization and escaping of settings to prevent Stored Cross-Site Scripting attacks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-13603

Affected Products

Wise Forms