PT-2025-1902 · WordPress · Contact Form Maker
Hassan Khan Yusufzai
+1
·
Published
2025-01-11
·
Updated
2025-05-17
·
CVE-2024-12587
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
The vulnerable software is the Contact Form Master WordPress plugin, with versions up to 1.0.7 being affected.
The vulnerability is a Reflected Cross-Site Scripting (XSS) vulnerability, which occurs because the plugin does not sanitize and escape a parameter before outputting it back in the page.
This could be used against high privilege users, such as admins.
There is a public reference to this vulnerability, identified as CVE-2024-12587.
No information is provided about whether this vulnerability has been exploited by attackers or the number of Internet users that can be affected.
The vulnerability can be exploited by manipulating a parameter that is not properly sanitized and escaped by the plugin, allowing an attacker to inject malicious code into the page.
#CVE-2024-12587 #ContactFormMaster #WordPressPlugin #ReflectedXSS #CrossSiteScripting
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form Maker