PT-2021-16084 · WordPress · Contact Form 7 Captcha
Dc11
·
Published
2021-08-23
·
Updated
2022-07-28
·
CVE-2021-24565
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contact Form 7 Captcha WordPress plugin versions prior to 0.0.9
Description
The issue concerns a lack of CSRF check when saving settings, allowing an attacker to manipulate a logged-in user with manage options privileges into changing them. Additionally, the settings are not properly escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
Recommendations
For versions prior to 0.0.9, update to version 0.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation. Avoid using the plugin's settings until the issue is resolved.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contact Form 7 Captcha