CVE-2015-9295: XSS
Published Aug 13, 2019
·Updated
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
Affected Software
1 affected component
Bestwebsoft Contact Form Wordpress<3.96
Event History
Aug 13, 2019
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the contact-form-plugin plugin before version 3.96 of WordPress?
The vulnerability ID for the contact-form-plugin plugin before version 3.96 of WordPress is CVE-2015-9295.
2
What is the severity of CVE-2015-9295?
The severity of CVE-2015-9295 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2015-9295?
The affected software for CVE-2015-9295 is the contact-form-plugin plugin before version 3.96 for WordPress.
4
What is the CWE category for CVE-2015-9295?
The CWE category for CVE-2015-9295 is CWE-79 (Cross-Site Scripting).
5
How do I fix the XSS vulnerability in the contact-form-plugin plugin?
To fix the XSS vulnerability in the contact-form-plugin plugin, you should update to version 3.96 or higher.