cformsII <= 10.4 - Cross-Site Scripting
mediumThe cforms2 plugin before 10.5 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 10.5
- Fixed in:
- 10.5
- Disclosed:
- Oct 15, 2014
plugin
6 known security issues reported for the Cforms WordPress plugin. Most recent disclosed Oct 15, 2014.
Running Cforms on your site? Check whether your installed version is affected.
Scan your site freeThe cforms2 plugin before 10.5 for WordPress has XSS.
The Cforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 10.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
[en] Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
[en] PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and the code exits with a fatal error due...
The cformsII plugin (slug: cforms) and its fork (slug: cforms2) have a CAPTCHA Bypass vulnerability. The MD5 hash for matching the answer is sent with the forms and so it can be overwritten. This is fixed in the fork (cforms2) with version 14.11 (see changelog for confirmation). The original delicious:days version (cfo...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free