The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 203,663 live websites that are affected by CVE-2024-10593.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 203,663 live websites (39% of WPForms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 185 versions ( 87% of all versions) |
| 57,325 websites | |
| 20,118 websites | |
| 11,539 websites | |
| 10,758 websites | |
| 7,297 websites | |
| 6,030 websites | |
| 5,796 websites | |
| 5,290 websites | |
| 5,146 websites | |
| 4,673 websites |
| .com | 87,750 websites |
| .de | 10,100 websites |
| .org | 9,150 websites |
| .co.uk | 6,380 websites |
| .nl | 5,489 websites |
| .it | 5,199 websites |
| .fr | 4,875 websites |
| .com.br | 4,724 websites |
| .net | 4,407 websites |
| .pl | 3,522 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.******.com | *** | ||
| ****************.com | *,*** | ||
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| *******.org | *,*** | ||
| *************.com | *,*** | ||
| ****.bg | *,*** | ||
| ****************.org | **,*** | ||
| ***********.com | **,*** | ||
| *********************.es | **,*** |
FAQ