CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-13829: WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure

5.3 CVSS

Description

The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.0.8 via the 'attachments.php' file. This makes it possible for unauthenticated attackers to extract sensitive data including files uploaded via forms.

Classification

CVE ID: CVE-2024-13829

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

Vendor: tripetto

Product: WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 23.9% (scored less or equal to compared to others)

EPSS Date: 2025-03-06 (when was this score calculated)

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/0a938042-bad6-4fe0-8905-148d07a22996?source=cve
https://plugins.trac.wordpress.org/browser/tripetto/trunk/lib/attachments.php
https://plugins.trac.wordpress.org/changeset/3231968/

Timeline