****************************
#Exploit Title: contactform7 - Cross Site Scripting Vulnerability (XSS)
#Date:  2022-06-13 
#Exploit Author: Mahdi Karimi
#Vendor Homepage: https://contactform7.com/
#Software Link: https://wordpress.org/plugins/contact-form-7/
#Tested On: windows 10


Proof of Concept:
1- localhost/contact-form-7/admin/admin.php > [XSS Inject Payload ]

Demo:     echo echo esc_attr($_REQUEST['page']); 

        requires:
            260: 
            ⇓ function wpcf7_admin_management_page()


**************************************************
#Discovered by: Mahdi Karimi
#Email : mjoker22mjoker22@gmail.com
**************************************************