The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 9,148 live websites that are affected by CVE-2024-8633.
Product | |
Category | Form Builders |
Vulnerable Domains | 9,148 live websites (64.31% of Form Maker install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 257 versions ( 58.14% of all versions) |
![]() | 3,627 websites |
![]() | 1,014 websites |
![]() | 481 websites |
![]() | 386 websites |
![]() | 369 websites |
![]() | 248 websites |
![]() | 215 websites |
![]() | 180 websites |
![]() | 176 websites |
![]() | 161 websites |
.com | 3,796 websites |
.org | 705 websites |
.de | 469 websites |
.nl | 352 websites |
.co.uk | 254 websites |
.net | 232 websites |
.ru | 211 websites |
.it | 206 websites |
.fr | 162 websites |
.ch | 145 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | *,*** | |
********.nl | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
*****.eu | ![]() | ***,*** | |
*************.***.au | ![]() | ***,*** | |
*******.*****.ee | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
******************.org | ![]() | ***,*** | |
******************.com | ![]() | ***,*** |
FAQ