WordPress Plugin Vulnerabilities
Contact Form 7 Database Addon < 1.2.6.2 - Unauthenticated Stored Cross-Site Scripting
Description
The plugin does not escape the key data before outputting it in admin pages, which could lead to Stored Cross-Site Scripting issues
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ex.Mi
Verified
No
WPVDB ID
Timeline
Publicly Published
2021-11-12 (about 4 years ago)
Added
2021-12-22 (about 4 years ago)
Last Updated
2022-04-16 (about 4 years ago)