The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 9,337 live websites that are affected by CVE-2024-10562.
Product | |
Category | Form Builders |
Vulnerable Domains | 9,337 live websites (65.64% of Form Maker install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 260 versions ( 58.82% of all versions) |
![]() | 3,704 websites |
![]() | 1,040 websites |
![]() | 491 websites |
![]() | 392 websites |
![]() | 380 websites |
![]() | 254 websites |
![]() | 220 websites |
![]() | 183 websites |
![]() | 180 websites |
![]() | 162 websites |
.com | 3,872 websites |
.org | 721 websites |
.de | 476 websites |
.nl | 358 websites |
.co.uk | 261 websites |
.net | 236 websites |
.ru | 215 websites |
.it | 211 websites |
.fr | 165 websites |
.ch | 147 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | *,*** | |
********.nl | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
*****.eu | ![]() | ***,*** | |
*************.***.au | ![]() | ***,*** | |
*******.*****.ee | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
******************.org | ![]() | ***,*** | |
******************.com | ![]() | ***,*** |
FAQ