Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 04 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:incsub:forminator:*:*:*:*:free:wordpress:*:* |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T01:59:49.388Z
Reserved: 2024-04-12T01:58:19.390Z
Link: CVE-2024-31857
Updated: 2024-04-23T15:38:16.799Z
Status : Analyzed
Published: 2024-04-23T05:15:49.377
Modified: 2025-04-04T13:03:08.680
Link: CVE-2024-31857
No data.
OpenCVE Enrichment
No data.
Weaknesses