PT-2026-3822 · Getsimple Cms+1 · My Smtp Contact Plugin+1

Bobby Cooke

·

Published

2026-01-21

·

Updated

2026-05-12

·

CVE-2021-47870

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GetSimple CMS My SMTP Contact Plugin version 1.1.2
Description A Stored Cross-Site Scripting (XSS) issue exists where the plugin fails to properly sanitize user input. Although the htmlspecialchars() function is used for sanitization, it can be bypassed by providing dangerous characters as escaped hex bytes. This allows an attacker to inject arbitrary client-side code that executes within the administrator's browser when they visit a malicious page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47870

Affected Products

My Smtp Contact Plugin
Getsimple Cms