CVE-2024-7056

WPForms < 1.9.1.6 - Admin+ Stored XSS

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 172,551 live websites that are affected by CVE-2024-7056.

Run a Free Instant Scan




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains172,551 live websites (36% of WPForms install base)
Vulnerable Versions
  • from 0 through 1.9.1.6
Vulnerable Versions Count180 versions ( 84% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 25, 2024
  • Updated - Nov 13, 2025

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-7056
United States48,325 websites



Germany17,518 websites
France9,743 websites
GB8,808 websites
Italy6,445 websites
Netherlands5,063 websites
Spain4,651 websites
India4,525 websites
Brazil4,432 websites
Poland4,016 websites

Website Distribution by TLD

Number of websites using CVE-2024-7056
.com74,068 websites
.de8,901 websites
.org7,801 websites
.co.uk5,145 websites
.nl4,620 websites
.it4,587 websites
.fr4,145 websites
.com.br4,071 websites
.net3,694 websites
.pl3,018 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7056

Top websites that are affected by CVE-2024-7056. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States*,***
******.com United States*,***
******.com United States*,***
*******.org Germany*,***
*************.com United States*,***
****.bg Bulgaria*,***
****************.org United States**,***
***********.com Italy**,***
*********************.es Spain**,***
*********.com United States**,***
See full domain list

FAQ

CVE-2024-7056 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms
A total of 172,551 websites have been identified as vulnerable to CVE-2024-7056, based on global website indexing conducted by WebTechSurvey.
The WPForms is affected by the CVE-2024-7056 vulnerability.
WPForms versions up to 1.9.1.6 are vulnerable to CVE-2024-7056.
CVE-2024-7056 is resolved in version 1.9.1.6 of WPForms.