Skip to main content
Vulnerability Database/CVE-2024-29777

CVE-2024-29777: Incsub Forminator XSS Vulnerability

CVE-2024-29777 is a cross-site scripting vulnerability in Incsub Forminator plugin that enables attackers to inject malicious scripts. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2024-29777 Overview

CVE-2024-29777 is a reflected Cross-Site Scripting (XSS) vulnerability [CWE-79] affecting the WPMU DEV Forminator plugin for WordPress. The flaw stems from improper neutralization of user input during web page generation. It affects Forminator versions from an unspecified initial release through 1.29.0 in both free and pro editions. An attacker can craft a malicious URL that executes arbitrary JavaScript in the victim's browser when visited. The scope change in the CVSS vector indicates the vulnerable component can affect resources beyond its own security authority, making session hijacking and credential theft feasible against site administrators.

Critical Impact

Successful exploitation allows attackers to execute arbitrary JavaScript in the context of a victim's browser session, enabling theft of session cookies, administrative account takeover, and defacement of affected WordPress sites.

Affected Products

  • WPMU DEV Forminator (free edition) for WordPress — versions up to and including 1.29.0
  • WPMU DEV Forminator (pro edition) for WordPress — versions up to and including 1.29.0
  • WordPress sites running the Forminator plugin for form, poll, and quiz building

Discovery Timeline

  • 2024-03-27 - CVE-2024-29777 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-29777

Vulnerability Analysis

The Forminator plugin fails to sanitize or escape user-supplied input before reflecting it into HTTP responses. This weakness, classified under CWE-79: Improper Neutralization of Input During Web Page Generation, produces a reflected XSS condition. Attackers deliver a crafted link to a targeted user, typically through phishing or an embedded resource. When the victim loads the URL, the server reflects attacker-controlled markup into the rendered page, and the browser executes it in the trust context of the WordPress site.

The vulnerability requires user interaction, such as clicking a prepared link, but requires no authentication. Because the CVSS scope changes, injected scripts can access protected resources within the WordPress session, including administrator cookies if the victim holds elevated privileges. For technical details, see the Patchstack XSS Vulnerability Advisory.

Root Cause

The root cause is missing output encoding on request parameters consumed by the plugin's web-facing endpoints. Input flows from HTTP request data into the generated HTML response without being passed through WordPress escaping APIs such as esc_html(), esc_attr(), or wp_kses(). This leaves markup characters including <, >, and quotes unescaped in the rendered output.

Attack Vector

Exploitation occurs over the network with low attack complexity and no privileges required. The attacker constructs a URL containing a JavaScript payload inside a vulnerable parameter processed by Forminator. The victim is enticed to click the link, which triggers the browser to execute the injected script under the origin of the hosting WordPress site. Payloads commonly perform cookie exfiltration, forced form submissions, or in-browser account hijacking against logged-in administrators. See the Patchstack Forminator Plugin Analysis for additional context.

Detection Methods for CVE-2024-29777

Indicators of Compromise

  • HTTP requests to Forminator endpoints containing URL-encoded <script>, onerror=, onload=, or javascript: payloads in query parameters.
  • Web server access logs showing unusually long query strings or encoded HTML entities targeting Forminator form, poll, or quiz URLs.
  • Outbound browser requests from administrative sessions to unfamiliar domains shortly after accessing a Forminator-related URL.
  • Unexpected creation of WordPress administrator accounts or modification of user roles following administrator browsing activity.

Detection Strategies

  • Deploy a Web Application Firewall (WAF) rule set that inspects query parameters and POST bodies for reflected XSS signatures targeting WordPress plugins.
  • Enable WordPress audit logging to correlate administrator actions with inbound requests containing suspicious payloads.
  • Perform static analysis of installed plugin files to confirm the Forminator version is 1.29.0 or earlier and schedule an upgrade.

Monitoring Recommendations

  • Monitor web server logs for repeated 200 responses to Forminator URLs that contain reflected characters such as %3Cscript%3E or %22onerror%3D.
  • Alert on administrator sessions originating from unexpected IP ranges or user-agent strings following phishing campaigns.
  • Track Content Security Policy (CSP) violation reports for inline script execution on pages that render Forminator content.

How to Mitigate CVE-2024-29777

Immediate Actions Required

  • Update WPMU DEV Forminator to a version later than 1.29.0 on all WordPress installations, including staging and development environments.
  • Audit WordPress administrator accounts for unauthorized additions or role changes created after March 2024.
  • Invalidate active administrator sessions and force password resets if compromise is suspected.
  • Review web server logs for prior requests containing XSS payloads directed at Forminator endpoints.

Patch Information

WPMU DEV addressed the vulnerability in a release following 1.29.0. Administrators should update through the WordPress plugin dashboard or by downloading the current release from the vendor. Refer to the Patchstack XSS Vulnerability Advisory for fixed version information and remediation guidance.

Workarounds

  • Temporarily deactivate the Forminator plugin on sites that cannot immediately upgrade, especially those exposing public forms to unauthenticated users.
  • Deploy WAF rules that block requests containing common XSS patterns such as <script, onerror=, or javascript: in query strings targeting plugin paths.
  • Enforce a strict Content Security Policy that disallows inline script execution and restricts script sources to trusted origins.
  • Restrict administrator access to the WordPress backend using IP allowlisting or multi-factor authentication to reduce the impact of session hijacking.
bash
# Example WordPress CLI upgrade command
wp plugin update forminator --path=/var/www/html

# Verify installed version is above 1.29.0
wp plugin get forminator --field=version --path=/var/www/html

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.