Lucene search

K
cvelistPatchstackCVELIST:CVE-2021-36913
HistorySep 29, 2022 - 12:00 a.m.

CVE-2021-36913 Redirection for Contact Form 7 <= 2.4.0 - Unauthenticated Options Change and Content Injection vulnerability

2022-09-2900:00:00
CWE-284
Patchstack
www.cve.org
cve-2021-36913
redirection for contact form 7 plugin
unauthenticated options change
content injection
wordpress
accessibe

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N

0.001 Low

EPSS

Percentile

26.7%

Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.

CNA Affected

[
  {
    "vendor": "Qube One",
    "product": "Redirection for Contact Form 7 (WordPress plugin)",
    "versions": [
      {
        "version": "<= 2.4.0",
        "status": "affected",
        "lessThanOrEqual": "2.4.0",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N

0.001 Low

EPSS

Percentile

26.7%

Related for CVELIST:CVE-2021-36913