Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vigov5

Researcher fromSunCSR
#38751of 53,630
7.2Total CVSS
Vulnerabilities · 1
PT-2021-15670
7.2
2021-03-18
WordPress · Contact Form Submissions · CVE-2021-24125
Name of the Vulnerable Software and Affected Versions: Contact Form Submissions WordPress plugin versions 1.6.4 and earlier Contact Form Submissions WordPress plugin versions prior to 1.7.1 Description: The issue arises from unvalidated input in the Contact Form Submissions WordPress plugin, which could lead to SQL injection in the `wpcf7 contact form` GET parameter when a high privilege user (admin+) submits a filter request. Recommendations: For versions 1.6.4 and earlier, update to version 1.7.1 or later. For versions prior to 1.7.1, update to version 1.7.1 or later.