CVE-2024-7056

WPForms < 1.9.1.6 - Admin+ Stored XSS

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 322,428 live websites that are affected by CVE-2024-7056.

Test my site




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains322,428 live websites (57.63% of WPForms install base)
Vulnerable Versions
  • from 0 before 1.9.1.6
Vulnerable Versions Count207 versions ( 93.24% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 25, 2024
  • Updated - Nov 25, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-7056 usage by Country

United States115,792 websites



Germany40,374 websites
France21,151 websites
GB13,514 websites
Cyprus13,316 websites
Netherlands8,444 websites
Poland7,087 websites
Spain6,853 websites
Italy5,907 websites
Russia5,327 websites

CVE-2024-7056 usage by TLD

.com144,138 websites
.de15,513 websites
.org15,173 websites
.co.uk10,091 websites
.nl8,654 websites
.fr8,089 websites
.com.br7,315 websites
.net7,120 websites
.com.au6,156 websites
.pl5,755 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7056

Top websites that are affected by CVE-2024-7056. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.domains United States*,***
************.com United States*,***
********.com Germany*,***
****************.com United States*,***
*******.com Netherlands*,***
************.com United States*,***
******.com United States*,***
******.com United States*,***
***********************.com United States*,***
*************.com Cyprus*,***
See full domain list

FAQ

CVE-2024-7056 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms
A total of 322,428 websites have been identified as vulnerable to CVE-2024-7056, discovered through global website indexing conducted by WebTechSurvey.
WPForms is susceptible to CVE-2024-7056 vulnerability.
WPForms versions before 1.9.1.6 are vulnerable to CVE-2024-7056.
Version 1.9.1.6 of WPForms addresses the CVE-2024-7056 security vulnerability.