CVE-2024-6725

Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 25,400 live websites that are affected by CVE-2024-6725.

Test my site




Affected Software

Product  Formidable Forms
Category Wordpress Plugins
Vulnerable Domains25,400 live websites (39.40% of Formidable Forms install base)
Vulnerable Versions
  • from 0 through 6.11.1
Vulnerable Versions Count272 versions ( 94.12% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 31, 2024
  • Updated - Aug 1, 2024

Credits

  • D.Sim (finder)

CVE-2024-6725 usage by Country

United States12,027 websites



Germany2,038 websites
France1,850 websites
GB1,433 websites
Netherlands777 websites
Australia635 websites
Canada601 websites
Sweden548 websites
Italy470 websites
Spain459 websites

CVE-2024-6725 usage by TLD

.com12,354 websites
.org1,308 websites
.co.uk1,281 websites
.de899 websites
.nl820 websites
.com.au812 websites
.fr791 websites
.ca674 websites
.net488 websites
.se431 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-6725

Top websites that are affected by CVE-2024-6725. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
************.**.**.uk GB**,***
********.**.**.uk GB**,***
**************.com United States**,***
********.ru Russia**,***
*******************.org United States**,***
**************.org United States**,***
****.**.uk United States**,***
*******.com France**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2024-6725 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Formidable Forms
A total of 25,400 websites have been identified as vulnerable to CVE-2024-6725, discovered through global website indexing conducted by WebTechSurvey.
Formidable Forms is susceptible to CVE-2024-6725 vulnerability.
Formidable Forms versions before, and including, 6.11.1 are vulnerable to CVE-2024-6725.