PT-2021-15670 · WordPress · Contact Form Submissions

Minhtuanact

+1

·

Published

2021-03-18

·

Updated

2022-05-27

·

CVE-2021-24125

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Contact Form Submissions WordPress plugin versions 1.6.4 and earlier Contact Form Submissions WordPress plugin versions prior to 1.7.1
Description: The issue arises from unvalidated input in the Contact Form Submissions WordPress plugin, which could lead to SQL injection in the wpcf7 contact form GET parameter when a high privilege user (admin+) submits a filter request.
Recommendations: For versions 1.6.4 and earlier, update to version 1.7.1 or later. For versions prior to 1.7.1, update to version 1.7.1 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24125

Affected Products

Contact Form Submissions