PT-2021-15670 · WordPress · Contact Form Submissions
Minhtuanact
+1
·
Published
2021-03-18
·
Updated
2022-05-27
·
CVE-2021-24125
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Contact Form Submissions WordPress plugin versions 1.6.4 and earlier
Contact Form Submissions WordPress plugin versions prior to 1.7.1
Description:
The issue arises from unvalidated input in the Contact Form Submissions WordPress plugin, which could lead to SQL injection in the
wpcf7 contact form GET parameter when a high privilege user (admin+) submits a filter request.Recommendations:
For versions 1.6.4 and earlier, update to version 1.7.1 or later.
For versions prior to 1.7.1, update to version 1.7.1 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form Submissions