CVE-2013-7475: XSS
Published Aug 13, 2019
·Updated
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
Affected Software
1 affected component
Bestwebsoft Contact Form Wordpress<3.52
Event History
Aug 13, 2019
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
Description
Frequently Asked Questions
1
What is CVE-2013-7475?
CVE-2013-7475 is a vulnerability in the contact-form-plugin plugin before version 3.52 for WordPress that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2013-7475?
CVE-2013-7475 has a severity level of medium, with a CVSS score of 6.1.
3
What software is affected by CVE-2013-7475?
The Bestwebsoft Contact Form plugin versions up to, but not including, 3.52 for WordPress are affected by CVE-2013-7475.
4
How can I fix CVE-2013-7475?
To fix CVE-2013-7475, update the contact-form-plugin plugin to version 3.52 or higher.
5
Where can I find more information about CVE-2013-7475?
Additional information about CVE-2013-7475 can be found at the official WordPress plugin page: https://wordpress.org/plugins/contact-form-plugin/#developers