CVE-2024-13403

WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 461,908 live websites that are affected by CVE-2024-13403.

Test my site




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains461,908 live websites (82.56% of WPForms install base)
Vulnerable Versions
  • from 0 through 1.9.3.1
Vulnerable Versions Count214 versions ( 96.40% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 4, 2025
  • Updated - Feb 4, 2025

Credits

  • Asaf Mozes (finder)

CVE-2024-13403 usage by Country

United States180,769 websites



Germany57,847 websites
France29,370 websites
GB19,553 websites
Cyprus18,241 websites
Netherlands12,984 websites
Spain8,939 websites
Poland8,929 websites
Italy7,792 websites
Denmark6,586 websites

CVE-2024-13403 usage by TLD

.com212,227 websites
.de24,711 websites
.org22,730 websites
.co.uk15,342 websites
.nl13,540 websites
.fr11,611 websites
.net10,133 websites
.com.au9,025 websites
.com.br8,704 websites
.pl7,207 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-13403

Top websites that are affected by CVE-2024-13403. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.*******.io Germany*,***
***.domains United States*,***
************.com United States*,***
**********.com United States*,***
********.com Germany*,***
****************.com United States*,***
*******.com Netherlands*,***
************.com United States*,***
************.net United States*,***
******.com United States*,***
See full domain list

FAQ

CVE-2024-13403 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms
A total of 461,908 websites have been identified as vulnerable to CVE-2024-13403, discovered through global website indexing conducted by WebTechSurvey.
WPForms is susceptible to CVE-2024-13403 vulnerability.
WPForms versions before, and including, 1.9.3.1 are vulnerable to CVE-2024-13403.