CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-10504: ARForms Builder < 1.7.1 - Unauthenticated Stored XSS

Description

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

Classification

CVE ID: CVE-2024-10504

Problem Types

CWE-79 Cross-Site Scripting (XSS)

Affected Products

Vendor: Unknown

Product: Contact Form, Survey, Quiz & Popup Form Builder

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 15.33% (scored less or equal to compared to others)

EPSS Date: 2025-06-13 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-10504
https://wpscan.com/vulnerability/9a22df11-0e24-4248-a8f3-da8f23ccb313/

Timeline