CVE-2024-6130

Form Maker by 10Web < 1.15.26 - Admin+ Stored XSS

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)


We have discovered 8,828 live websites that are affected by CVE-2024-6130.

Test my site




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains8,828 live websites (62.06% of Form Maker install base)
Vulnerable Versions
  • from 0 before 1.15.26
Vulnerable Versions Count255 versions ( 57.69% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 1, 2024
  • Updated - Oct 30, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-6130 usage by Country

United States3,506 websites



Germany973 websites
France457 websites
GB364 websites
Netherlands354 websites
Italy242 websites
Russia207 websites
Denmark176 websites
Canada172 websites
Switzerland156 websites

CVE-2024-6130 usage by TLD

.com3,658 websites
.org694 websites
.de449 websites
.nl336 websites
.co.uk236 websites
.net226 websites
.ru205 websites
.it196 websites
.fr152 websites
.ch141 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-6130

Top websites that are affected by CVE-2024-6130. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
********.nl Netherlands***,***
******.com United States***,***
*****.eu Slovenia***,***
*************.***.au Australia***,***
*******.*****.ee Estonia***,***
****************.org United States***,***
****************.org United States***,***
******************.org United States***,***
******************.com United States***,***
See full domain list

FAQ

CVE-2024-6130 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Form Maker
A total of 8,828 websites have been identified as vulnerable to CVE-2024-6130, discovered through global website indexing conducted by WebTechSurvey.
Form Maker is susceptible to CVE-2024-6130 vulnerability.
Form Maker versions before 1.15.26 are vulnerable to CVE-2024-6130.
Version 1.15.26 of Form Maker addresses the CVE-2024-6130 security vulnerability.