CVE-2024-8756

Quform - WordPress Form Builder <= 2.20.0 - Unauthenticated Sensitive Information Exposure

The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the 'saveUploadedFile' function. This makes it possible for unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users. Files uploaded via forms created before version 2.21.0 will remain vulnerable to exposure after upgrading. To fully patch the plugin, site administrators should download any previously uploaded files, delete previously existing files and forms, and create the forms again after upgrading to version 2.21.0.


We have discovered 90 live websites that are affected by CVE-2024-8756.

Run a Free Instant Scan




Affected Software

Product  Quform WordPress Form Builder
Category Wordpress Plugins
Vulnerable Domains90 live websites (27% of Quform WordPress Form Builder install base)
Vulnerable Versions
  • from 0 through 2.20
Vulnerable Versions Count14 versions ( 61% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Nov 9, 2024
  • Updated - Nov 12, 2024

Credits

  • Khayal Farzaliyev (finder)

Website Distribution by Country

Number of websites using CVE-2024-8756
United States23 websites



Iran13 websites
Germany6 websites
France5 websites
Russia5 websites
Switzerland4 websites
Spain4 websites
Netherlands3 websites
Belgium2 websites
Bulgaria2 websites

Website Distribution by TLD

Number of websites using CVE-2024-8756
.com40 websites
.ru4 websites
.org4 websites
.de4 websites
.ch3 websites
.be2 websites
.pl2 websites
.co.uk2 websites
.com.br2 websites
.nl2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8756

Top websites that are affected by CVE-2024-8756. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com Iran*,***,***
**********.***.br United States*,***,***
***********.nl Netherlands*,***,***
*****.agency Iran*,***,***
********.eu Germany*,***,***
*********.ru Russia*,***,***
*******.com United States*,***,***
*****************.de Netherlands*,***,***
*******.com France*,***,***
****************.lk Sri Lanka*,***,***
See full domain list

FAQ

CVE-2024-8756 is Exposure of Sensitive Information to an Unauthorized Actor in Quform WordPress Form Builder
A total of 90 websites have been identified as vulnerable to CVE-2024-8756, based on global website indexing conducted by WebTechSurvey.
The Quform WordPress Form Builder is affected by the CVE-2024-8756 vulnerability.
Quform WordPress Form Builder versions up to and including 2.20 are vulnerable to CVE-2024-8756.