PT-2025-1839 · WordPress · Cf7 Wow Styler

Arkadiusz Hydzik

·

Published

2025-01-07

·

Updated

2025-01-07

·

CVE-2024-12419

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress versions prior to 1.7.1
Description The issue is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The functionality is also vulnerable to Reflected Cross-Site Scripting. Although version 1.7.0 patched the Reflected XSS issue, the arbitrary shortcode execution issue remains.
Recommendations For versions prior to 1.7.1, update to version 1.7.1 or later to resolve the issue. As a temporary workaround, consider disabling the execution of shortcodes until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-12419

Affected Products

Cf7 Wow Styler