Strategic Overview
- Status
- Patched in 5.2.46
- Affected Plugin
- Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
- Affected Version
<= 5.2.45- CVSS
- 5.3Medium
- Weakness type
- CWE-75 · Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
- CVE
CVE-2024-9940
At a glance
CVE-2024-9940 is a medium-severity Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in the Calculated Fields Form WordPress plugin, affecting versions <= 5.2.45. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 5.2.46; sites on affected versions should update now. Disclosed October 2024, reported by Max Boll (_b0lli).
Vulnerability Overview
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
The product does not adequately filter user-controlled input for special elements with control implications.
Remediation
Update to version 5.2.46, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Calculated Fields Form 5.2.46 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
- 9.8Calculated Fields Form <= 1.0.11 CSRF to SQL Injection
- 7.2CVE-2024-2020: Calculated Fields Form Professional Stored XSS
CVE-2024-2020 - 6.4CVE-2026-3986: Calculated Fields Form <= 5.4.5.0 Stored XSS
CVE-2026-3986 - 6.4CVE-2024-0963: Calculated Fields Form <= 1.2.52 Stored XSS
CVE-2024-0963 - 6.1CVE-2024-29759: Calculated Fields Form <= 1.2.54 Reflected XSS
CVE-2024-29759 - 5.4CVE-2020-7228: Calculated Fields Form <= 1.0.353 Stored XSS
CVE-2020-7228 - 5.3CVE-2024-12601: Calculated Fields Form <= 5.2.63 Denial of Service
CVE-2024-12601 - 4.4CVE-2024-13381: Calculated Fields Form <= 5.2.61 Stored XSS
CVE-2024-13381
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C