CVE-2024-9940

Calculated Fields Form <= 5.2.45 - HTML Injection

2024-10-16 00:00
Max Boll (_b0lli)

Strategic Overview

Status
Patched in 5.2.46
Affected Version
<= 5.2.45
CVSS
5.3Medium
Weakness type
CWE-75 · Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
CVE
CVE-2024-9940
View all Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More vulnerabilities

At a glance

CVE-2024-9940 is a medium-severity Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in the Calculated Fields Form WordPress plugin, affecting versions <= 5.2.45. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 5.2.46; sites on affected versions should update now. Disclosed October 2024, reported by Max Boll (_b0lli).

Vulnerability Overview

The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.

CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

The product does not adequately filter user-controlled input for special elements with control implications.

Remediation

Update to version 5.2.46, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Calculated Fields Form 5.2.46 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C