The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
We have discovered 8,828 live websites that are affected by CVE-2024-6130.
Product | |
Category | Form Builders |
Vulnerable Domains | 8,828 live websites (62.06% of Form Maker install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 255 versions ( 57.69% of all versions) |
![]() | 3,506 websites |
![]() | 973 websites |
![]() | 457 websites |
![]() | 364 websites |
![]() | 354 websites |
![]() | 242 websites |
![]() | 207 websites |
![]() | 176 websites |
![]() | 172 websites |
![]() | 156 websites |
.com | 3,658 websites |
.org | 694 websites |
.de | 449 websites |
.nl | 336 websites |
.co.uk | 236 websites |
.net | 226 websites |
.ru | 205 websites |
.it | 196 websites |
.fr | 152 websites |
.ch | 141 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | *,*** | |
********.nl | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
*****.eu | ![]() | ***,*** | |
*************.***.au | ![]() | ***,*** | |
*******.*****.ee | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
******************.org | ![]() | ***,*** | |
******************.com | ![]() | ***,*** |
FAQ