Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-62752
HistoryMar 15, 2022 - 12:00 a.m.

WordPress Contact Form X plugin cross-site scripting vulnerability

2022-03-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.002 Low

EPSS

Percentile

52.6%

WordPress is a set of blogging platforms developed by the Wordpress Foundation using the PHP language. WordPress plugin is an application plugin for WordPress. A cross-site scripting vulnerability exists in WordPress Contact Form X plugin version 2.4 and earlier. The vulnerability stems from a lack of data validation filtering of user-supplied data and output in the &tab parameter. An attacker could exploit this vulnerability to execute JavaScript code.

CPENameOperatorVersion
wordpress contact form x pluginle2.4

0.002 Low

EPSS

Percentile

52.6%