CVE-2014-6445: XSS
Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6445?
CVE-2014-6445 is classified as a medium severity vulnerability due to its potential for cross-site scripting exploits.
How do I fix CVE-2014-6445?
To fix CVE-2014-6445, update the Contact Form 7 Integrations plugin to version 1.3.11 or later.
Which versions are affected by CVE-2014-6445?
CVE-2014-6445 affects Contact Form 7 Integrations plugin versions 1.0 through 1.3.10.
What types of attacks can occur due to CVE-2014-6445?
CVE-2014-6445 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
Who is primarily at risk from CVE-2014-6445?
Users of the affected versions of the Contact Form 7 Integrations plugin on WordPress are primarily at risk from CVE-2014-6445.