The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 461,908 live websites that are affected by CVE-2024-13403.
Product | |
Category | Form Builders |
Vulnerable Domains | 461,908 live websites (82.56% of WPForms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 214 versions ( 96.40% of all versions) |
![]() | 180,769 websites |
![]() | 57,847 websites |
![]() | 29,370 websites |
![]() | 19,553 websites |
![]() | 18,241 websites |
![]() | 12,984 websites |
![]() | 8,939 websites |
![]() | 8,929 websites |
![]() | 7,792 websites |
![]() | 6,586 websites |
.com | 212,227 websites |
.de | 24,711 websites |
.org | 22,730 websites |
.co.uk | 15,342 websites |
.nl | 13,540 websites |
.fr | 11,611 websites |
.net | 10,133 websites |
.com.au | 9,025 websites |
.com.br | 8,704 websites |
.pl | 7,207 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**.*******.io | ![]() | *,*** | |
***.domains | ![]() | *,*** | |
************.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
****************.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
************.com | ![]() | *,*** | |
************.net | ![]() | *,*** | |
******.com | ![]() | *,*** |
FAQ