Tripetto WordPress Plugin Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Tripetto WordPress form builder plugin, which is used for creating contact forms, surveys, and quizzes. This vulnerability affects versions of the plugin through 8.0.5.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed when users visit the affected site.

Remediation

Users of the Tripetto WordPress plugin should update to version 8.0.7 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
1.7
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.