Lucene search

K

Contact Form Submissions Project Security Vulnerabilities

cve
cve

CVE-2021-24125

Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)

7.2CVSS

7.2AI Score

0.001EPSS

2021-03-18 03:15 PM
24
cve
cve

CVE-2022-0248

The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact form requests before outputting them in the related submission. As a result, unauthenticated attacker could perform Cross-Site Scripting attacks against admins viewing the malicious ...

6.1CVSS

6.1AI Score

0.001EPSS

2022-03-14 03:15 PM
104