CVE-2024-10562

Form Maker by 10Web < 1.15.31 - Admin+ Stored XSS

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 9,337 live websites that are affected by CVE-2024-10562.

Test my site




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains9,337 live websites (65.64% of Form Maker install base)
Vulnerable Versions
  • from 0 before 1.15.31
Vulnerable Versions Count260 versions ( 58.82% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 7, 2025
  • Updated - Jan 7, 2025

Credits

  • Dmitrii Ingatyev (finder)
  • WPScan (coordinator)

CVE-2024-10562 usage by Country

United States3,704 websites



Germany1,040 websites
France491 websites
GB392 websites
Netherlands380 websites
Italy254 websites
Russia220 websites
Denmark183 websites
Canada180 websites
Switzerland162 websites

CVE-2024-10562 usage by TLD

.com3,872 websites
.org721 websites
.de476 websites
.nl358 websites
.co.uk261 websites
.net236 websites
.ru215 websites
.it211 websites
.fr165 websites
.ch147 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-10562

Top websites that are affected by CVE-2024-10562. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
********.nl Netherlands***,***
******.com United States***,***
*****.eu Slovenia***,***
*************.***.au Australia***,***
*******.*****.ee Estonia***,***
****************.org United States***,***
****************.org United States***,***
******************.org United States***,***
******************.com United States***,***
See full domain list

FAQ

CVE-2024-10562 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Form Maker
A total of 9,337 websites have been identified as vulnerable to CVE-2024-10562, discovered through global website indexing conducted by WebTechSurvey.
Form Maker is susceptible to CVE-2024-10562 vulnerability.
Form Maker versions before 1.15.31 are vulnerable to CVE-2024-10562.
Version 1.15.31 of Form Maker addresses the CVE-2024-10562 security vulnerability.