Contact Builder by Themify <= 1.4.5 - Email Injection
medium
The Contact Builder by Themify plugin is vulnerable to email injection in versions up to, and including 1.4.5. This makes it possible for attackers to forward contact form submissions as a "copy" to the contact-email supplied even when the setting is disabled. In addition, the contact-message does not do any input sani...
- CVSS:
- 5.3
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Jul 13, 2020
Builder Contact [builder-contact] < 1.4.6
unknown
The Contact Builder by Themify plugin is vulnerable to email injection in versions up to, and including 1.4.5. This makes it possible for attackers to forward contact form submissions as a "copy" to the contact-email supplied even when the setting is disabled. In addition, the contact-message does not do any input sani...
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Jul 13, 2020
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database