Rock Lobster, LLC Contact Form 5.8.5 for WordPress

CPE Details

Rock Lobster, LLC Contact Form 5.8.5 for WordPress
5.8.5
2024-07-01
16h30 +00:00
2024-07-01
16h30 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:rocklobster:contact_form_7:5.8.5:*:*:*:*:wordpress:*:*

Informations

Vendor

rocklobster

Product

contact_form_7

Version

5.8.5

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-4704 2024-06-27 06h00 +00:00 The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
6.1
Moyen
CVE-2024-2242 2024-03-13 21h32 +00:00 The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
6.1
Moyen