CVE-2022-0248
14.03.2022, 15:15
The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious submission
Vendor | Product | Version |
---|---|---|
contact_form_submissions_project | contact_form_submissions | 𝑥 < 1.7.3 |
𝑥
= Vulnerable software versions