CVE-2024-2258

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 8,651 live websites that are affected by CVE-2024-2258.

Test my site




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains8,651 live websites (60.82% of Form Maker install base)
Vulnerable Versions
  • from 0 through 1.15.24
Vulnerable Versions Count254 versions ( 57.47% of all versions)



Details

  • Published - Apr 27, 2024
  • Updated - Aug 1, 2024

Credits

  • Matthew Rollings (finder)

CVE-2024-2258 usage by Country

United States3,445 websites



Germany946 websites
France450 websites
GB355 websites
Netherlands351 websites
Italy235 websites
Russia204 websites
Denmark170 websites
Canada170 websites
Switzerland152 websites

CVE-2024-2258 usage by TLD

.com3,588 websites
.org692 websites
.de437 websites
.nl332 websites
.co.uk226 websites
.net224 websites
.ru194 websites
.it189 websites
.fr147 websites
.ch137 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2258

Top websites that are affected by CVE-2024-2258. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
********.nl Netherlands***,***
******.com United States***,***
*****.eu Slovenia***,***
*************.***.au Australia***,***
****************.org United States***,***
****************.org United States***,***
******************.org United States***,***
******************.com United States***,***
****.it Italy***,***
See full domain list

FAQ

A total of 8,651 websites have been identified as vulnerable to CVE-2024-2258, discovered through global website indexing conducted by WebTechSurvey.
Form Maker is susceptible to CVE-2024-2258 vulnerability.
Form Maker versions before, and including, 1.15.24 are vulnerable to CVE-2024-2258.