****************************
#Exploit Title: contactform7 - Cross Site Scripting Vulnerability (XSS)
#Date: 2022-06-13
#Exploit Author: Mahdi Karimi
#Vendor Homepage: https://contactform7.com/
#Software Link: https://wordpress.org/plugins/contact-form-7/
#Tested On: windows 10
Proof of Concept:
1- localhost/contact-form-7/admin/admin.php > [XSS Inject Payload ]
Demo: echo echo esc_attr($_REQUEST['page']);
requires:
260:
⇓ function wpcf7_admin_management_page()
**************************************************
#Discovered by: Mahdi Karimi
#Email : mjoker22mjoker22@gmail.com
**************************************************