CVE-2024-11223

WPForms < 1.9.2.3 - Admin+ Stored XSS

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 147,883 live websites that are affected by CVE-2024-11223.

Run a Free Instant Scan




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains147,883 live websites (36% of WPForms install base)
Vulnerable Versions
  • from 0 through 1.9.2.3
Vulnerable Versions Count186 versions ( 81% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 26, 2024
  • Updated - Dec 30, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-11223
United States39,526 websites



Germany14,200 websites
France8,447 websites
GB7,685 websites
Italy5,575 websites
Netherlands4,647 websites
Spain4,487 websites
India3,846 websites
Poland3,766 websites
Brazil3,698 websites

Website Distribution by TLD

Number of websites using CVE-2024-11223
.com62,619 websites
.de7,413 websites
.org6,424 websites
.co.uk4,223 websites
.nl4,064 websites
.it3,924 websites
.fr3,516 websites
.com.br3,372 websites
.net3,154 websites
.pl2,848 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11223

Top websites that are affected by CVE-2024-11223. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
****************.com United States*,***
******.com United States*,***
******.com United States*,***
*******.org Germany*,***
*************.com United States*,***
****.bg Bulgaria*,***
****************.org United States**,***
***********.com Italy**,***
*********.com United States**,***
See full domain list

FAQ

CVE-2024-11223 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms
A total of 147,883 websites have been identified as vulnerable to CVE-2024-11223, based on global website indexing conducted by WebTechSurvey.
The WPForms is affected by the CVE-2024-11223 vulnerability.
WPForms versions up to 1.9.2.3 are vulnerable to CVE-2024-11223.
CVE-2024-11223 is resolved in version 1.9.2.3 of WPForms.