Rock Lobster, LLC Contact Form 5.8.6 for WordPress

CPE Details

Rock Lobster, LLC Contact Form 5.8.6 for WordPress
5.8.6
2024-07-01
16h30 +00:00
2024-07-01
16h30 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:rocklobster:contact_form_7:5.8.6:*:*:*:*:wordpress:*:*

Informations

Vendor

rocklobster

Product

contact_form_7

Version

5.8.6

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-4704 2024-06-27 06h00 +00:00 The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
6.1
Medium
CVE-2024-2242 2024-03-13 21h32 +00:00 The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
6.1
Medium