The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 172,551 live websites that are affected by CVE-2024-7056.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 172,551 live websites (36% of WPForms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 180 versions ( 84% of all versions) |
| 48,325 websites | |
| 17,518 websites | |
| 9,743 websites | |
| 8,808 websites | |
| 6,445 websites | |
| 5,063 websites | |
| 4,651 websites | |
| 4,525 websites | |
| 4,432 websites | |
| 4,016 websites |
| .com | 74,068 websites |
| .de | 8,901 websites |
| .org | 7,801 websites |
| .co.uk | 5,145 websites |
| .nl | 4,620 websites |
| .it | 4,587 websites |
| .fr | 4,145 websites |
| .com.br | 4,071 websites |
| .net | 3,694 websites |
| .pl | 3,018 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.com | *,*** | ||
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| *******.org | *,*** | ||
| *************.com | *,*** | ||
| ****.bg | *,*** | ||
| ****************.org | **,*** | ||
| ***********.com | **,*** | ||
| *********************.es | **,*** | ||
| *********.com | **,*** |
FAQ