[Japanese]

JVNDB-2024-000097

WordPress Plugin "Forminator" vulnerable to cross-site scripting

Overview

WordPress Plugin "Forminator" provided by WPMU DEV assists building web forms. When accessing the page including the web form created with Forminator, some information from the URL may be embedded to the web form.
This feature processes the embedded information improperly, leading to cross-site scripting vulnerability (CWE-79).

Yoshimitsu Kato of Asterisk Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.1 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
Affected Products


WPMU DEV
  • Forminator versions prior to 1.34.1

Impact

When you follow a crafted URL and access the webpage having the web form created with Forminator, an arbitrary script may be executed on your web browser.
Solution

[Update the plugin and rebuild the web forms]
Update the plugin and rebuild the previously created web forms according to the information provided by the developer.
Vendor Information

WPMU DEV
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2024-45625
References

  1. JVN : JVN#65724976
Revision History

  • [2024/09/09]
      Web page was published