CVE-2024-9940
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.37%
- CWE
- CWE-75
- Published
- 2024-10-17
- Last modified
- 2026-03-13
Affected products
- codepeople Calculated Fields Form
Weakness type
Related vulnerabilities
- CVE-2024-58362 — SurrealDB before 1.5.5 Query Injection via RPC API
- CVE-2026-54771 — Langroid: handle_message() executes user-supplied tool JSON without sender verification
- CVE-2026-31908 — Apache APISIX: forward auth plugin allows header injection
- CVE-2026-29042 — Nuclio Shell Runtime Command Injection Leading to Privilege Escalation
- CVE-2026-27120 — Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
- CVE-2025-61911 — python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
- CVE-2025-50213 — Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator
- CVE-2023-1758 — Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaq