The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 322,428 live websites that are affected by CVE-2024-7056.
Product | |
Category | Form Builders |
Vulnerable Domains | 322,428 live websites (57.63% of WPForms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 207 versions ( 93.24% of all versions) |
![]() | 115,792 websites |
![]() | 40,374 websites |
![]() | 21,151 websites |
![]() | 13,514 websites |
![]() | 13,316 websites |
![]() | 8,444 websites |
![]() | 7,087 websites |
![]() | 6,853 websites |
![]() | 5,907 websites |
![]() | 5,327 websites |
.com | 144,138 websites |
.de | 15,513 websites |
.org | 15,173 websites |
.co.uk | 10,091 websites |
.nl | 8,654 websites |
.fr | 8,089 websites |
.com.br | 7,315 websites |
.net | 7,120 websites |
.com.au | 6,156 websites |
.pl | 5,755 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.domains | ![]() | *,*** | |
************.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
****************.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
************.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
***********************.com | ![]() | *,*** | |
*************.com | ![]() | *,*** |
FAQ