Contact Form Submissions <= 1.7.2 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission
- CVSS:
- 7.2
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- Feb 21, 2022
CVE-2022-0248 on NVD →
Contact Form Submissions <= 1.7 - Authenticated SQL Injection
high
Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)
- CVSS:
- 7.2
- Affected:
- up to 1.7
- Fixed in:
- 1.7.1
- Disclosed:
- Jan 3, 2021
CVE-2021-24125 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database