The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codepeople
Codepeople calculated Fields Form |
|
CPEs | cpe:2.3:a:codepeople:calculated_fields_form:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Codepeople
Codepeople calculated Fields Form |
|
Metrics |
ssvc
|
Thu, 17 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email. | |
Title | Calculated Fields Form <= 5.2.45 - HTML Injection | |
Weaknesses | CWE-75 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-17T02:06:05.303Z
Updated: 2024-10-17T16:10:28.112Z
Reserved: 2024-10-14T16:00:44.204Z
Link: CVE-2024-9940
Vulnrichment
Updated: 2024-10-17T16:10:19.828Z
NVD
Status : Awaiting Analysis
Published: 2024-10-17T02:15:04.277
Modified: 2024-10-18T12:53:04.627
Link: CVE-2024-9940
Redhat
No data.