CVE-2024-10056

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, and including, 4.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>vcita&#8217;s Contact Form is the ultimate way to capture and manage leads on your WordPress website.<br /> Create and integrate beautiful forms in seconds &#8211; customized to any purpose and perfectly match the website theme and design.</p> <h4>Contact Form Builder key features:</h4> <ul> <li>Easily create and embed responsive contact forms that look great on any device</li> <li>Full customisation of the contact form look and feel – layout, colors, size, fonts and more</li> <li>Easy to add, remove, edit and reorder contact form fields </li> <li>Create as many forms as you want and embed those on any website </li> <li>Select which fields are mandatory on you contact form</li> <li>Unlimited number of fields on your contact form</li> <li>Add any question you need to your contact form. vcita will show all the information your clients provided on a client card including their picture, age and more</li> <li>Multiple contact form field options to choose from: Text fields, numeric fields, text areas and dropdown fields on your contact form</li> <li>Language customisation for all contact form texts and labels</li> <li>Unlimited contact form entries </li> <li>Receive Email &amp; SMS notifications on any contact form submission, and provide immediate follow-up using any device.</li> <li>Manage all leads using vcita&#8217;s CRM tool. </li> <li>Export all contact form submissions and client information to Excel or CSV</li> <li>Send clients email confirmation for any contact form submission </li> <li>Easily search for contacts and follow up: take notes, edit contact information and track sent emails</li> </ul> <p>Learn more about our <a href="https://www.vcita.com/contact_form?invite=WP-contact" rel="nofollow ugc">Contact Form for WordPress</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
372K