Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9940


The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.


Published

2024-10-17T02:15:04.277

Last Modified

2025-06-05T16:40:26.147

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-75
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application codepeople calculated_fields_form < 5.2.46 Yes

References