The HTML Forms plugin for WordPress has a security flaw identified as CVE-2024-6243. This vulnerability, known as Stored Cross-Site Scripting (XSS), could allow an attacker with high-level access, such as an administrator, to inject malicious code into your website. When another user views the affected part of your site, this malicious code can run in their browser. This can happen even if WordPress’s built-in unfiltered_html setting is turned off.
CVE Details
- CVE ID: CVE-2024-6243
- Product: HTML Forms WordPress Plugin
- Published: July 22, 2024
- Severity: Medium
- Status: Analyzed
Affected Products
The HTML Forms plugin is vulnerable in all versions prior to 1.3.33. If you are currently using any version older than 1.3.33, your WordPress site could be at risk from this vulnerability.
Current Status
This vulnerability has been thoroughly analyzed and publicly disclosed. The details, including how it can be exploited, are known to the cybersecurity community.
Severity Level
This vulnerability is rated as Medium severity. While it specifically requires a high-privilege user, like an administrator, to successfully carry out an attack, the potential impact is significant. An attacker who exploits this flaw could take over user browser sessions, redirect visitors to harmful websites, or steal sensitive data such as session cookies.
Possible Solutions
To safeguard your WordPress website from this Stored Cross-Site Scripting vulnerability, the most critical step is to update your HTML Forms plugin. Ensure you are running version 1.3.33 or any newer release. Regularly updating your plugins is a fundamental security practice that helps protect your site from known vulnerabilities and ensures you benefit from the latest security patches.
References
- https://wpscan.com/vulnerability/f4097877-ba19-4738-a994-9593b9a5a635/


