The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all versions up to, and including, 8.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the uploaded file.
History

Fri, 28 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tripetto
Tripetto tripetto
Weaknesses CWE-79
CPEs cpe:2.3:a:tripetto:tripetto:*:*:*:*:*:wordpress:*:*
Vendors & Products Tripetto
Tripetto tripetto

Mon, 17 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Mar 2025 04:30:00 +0000

Type Values Removed Values Added
Description The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all versions up to, and including, 8.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the uploaded file.
Title WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-03-17T16:53:51.856Z

Reserved: 2025-01-16T21:09:55.087Z

Link: CVE-2024-13497

cve-icon Vulnrichment

Updated: 2025-03-17T16:53:47.910Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-15T05:15:45.713

Modified: 2025-03-28T15:22:59.280

Link: CVE-2024-13497

cve-icon Redhat

No data.