The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linksoftwarellc
Linksoftwarellc html Forms |
|
| CPEs | cpe:2.3:a:linksoftwarellc:html_forms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ibericode
Ibericode html Forms |
Linksoftwarellc
Linksoftwarellc html Forms |
Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-22T06:00:06.064Z
Updated: 2024-08-01T21:33:05.323Z
Reserved: 2024-06-21T13:19:50.613Z
Link: CVE-2024-6243
Updated: 2024-08-01T21:33:05.323Z
Status : Analyzed
Published: 2024-07-22T06:15:02.663
Modified: 2026-01-30T20:28:24.210
Link: CVE-2024-6243
No data.