RSS   Vulnerabilities for 'Contact form entries'   RSS

2022-01-24
 
CVE-2021-25079

CWE-79
 

 
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

 
 
CVE-2021-25080

CWE-79
 

 
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry

 

 >>> Vendor: Crmperks 2 Products
Contact form entries
Integration for constant contact and contact form 7\, wpforms\, elementor\, ninja


Copyright 2024, cxsecurity.com

 

Back to Top