CVE-2022-2187
17.07.2022, 11:15
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Vendor | Product | Version |
---|---|---|
contact_form_7_captcha_project | contact_form_7_captcha | 𝑥 < 0.1.2 |
𝑥
= Vulnerable software versions