CVE-2024-10182

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Cognito Forms is an easy-to-use online form builder that enables you to create everything from simple surveys to complex registration forms &#8211; no code required. Whether you’re using a pre-made template or starting from scratch, you can create forms to help your organization in just a matter of minutes.</p> <p>New to Cognito Forms? Watch a quick tutorial to get acquainted with the form builder, and learn how to create your first form!</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/8lZ7cK29C9U?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h3>Features</h3> <p><strong><a href="https://www.cognitoforms.com/product/data-collection?utm_source=wordpress&amp;utm_medium=referral&amp;utm_campaign=profile" rel="nofollow ugc">Data Collection</a></strong></p> <p>Format numbers for calculations, dates and times, add values to dropdowns and checkboxes, capture electronic signatures, and collect file uploads using our drag-and-drop form builder.</p> <p><strong><a href="https://www.cognitoforms.com/product/data-management?utm_source=wordpress&amp;utm_medium=referral&amp;utm_campaign=profile" rel="nofollow ugc">Data Management</a></strong></p> <p>Creating your form and sharing it with your customers is just step one – what happens to all that data after it gets submitted? In Cognito Forms, you can sort through and filter down your entries, create customized data sets, and perform multiple tasks at once.</p> <p><strong><a href="https://www.cognitoforms.com/product/integrations?utm_source=wordpress&amp;utm_medium=referral&amp;utm_campaign=profile" rel="nofollow ugc">Integrations</a></strong></p> <p>Use Zapier, Microsoft Power Automate or Make to exchange data with thousands of applications. Create workflows and automatically trigger tasks directly from your form entries. And quickly set it all up using either no-code visual interfaces or JSON.</p> <p><strong><a href="https://www.cognitoforms.com/product/logic-automation?utm_source=wordpress&amp;utm_medium=referral&amp;utm_campaign=profile" rel="nofollow ugc">Logic &amp; Automation</a></strong></p> <p>Set form behaviors and automate tasks using our visual conditional logic. Easily add text piping to make your forms more conversational. Or, enable actions that conditionally send notifications, include file attachments, perform calculations, or set limits in quantities and dates – all using our no-code/low-code visual interface.</p> <p><strong><a href="https://www.cognitoforms.com/product/security-compliance?utm_source=wordpress&amp;utm_medium=referral&amp;utm_campaign=profile" rel="nofollow ugc">Security &amp; Compliance</a></strong></p> <p>Quickly create additional protections for fields and forms. Set organizational controls by the individual form or folder. Manage access and account permissions. And stay compliant with HIPAA, GDPR, CCPA and other security regulations.</p> <p><strong><a href="https://www.cognitoforms.com/product/online-payment?utm_source=wordpress&amp;utm_medium=referral&amp;utm_campaign=profile" rel="nofollow ugc">Online Payment</a></strong></p> <p>Accept online payments directly through your forms – using Square, Stripe or PayPal. Whether you’re collecting a simple online donation or processing complex multi-variable transactions, you can do so easily on any of our plan levels.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
113K