WordPress Plugin Vulnerabilities

Contact Form 7 Database Addon < 1.2.6.2 - Unauthenticated Stored Cross-Site Scripting

Description

The plugin does not escape the key data before outputting it in admin pages, which could lead to Stored Cross-Site Scripting issues

Affects Plugins

Fixed in 1.2.6.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ex.Mi
Verified
No

Timeline

Publicly Published
2021-11-12 (about 4 years ago)
Added
2021-12-22 (about 4 years ago)
Last Updated
2022-04-16 (about 4 years ago)

Other