PT-2021-16084 · WordPress · Contact Form 7 Captcha

Dc11

·

Published

2021-08-23

·

Updated

2022-07-28

·

CVE-2021-24565

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contact Form 7 Captcha WordPress plugin versions prior to 0.0.9
Description The issue concerns a lack of CSRF check when saving settings, allowing an attacker to manipulate a logged-in user with manage options privileges into changing them. Additionally, the settings are not properly escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
Recommendations For versions prior to 0.0.9, update to version 0.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation. Avoid using the plugin's settings until the issue is resolved.

Exploit

Fix

XSS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24565

Affected Products

Contact Form 7 Captcha