First published: Tue Aug 13 2019(Updated: )
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mediaburst Contact Form 7 - Clockwork Sms | <2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18489 is classified as a medium severity vulnerability due to its XSS risk.
To fix CVE-2017-18489, update the contact-form-7-sms-addon plugin to version 2.4.0 or later.
Versions of the contact-form-7-sms-addon plugin before 2.4.0 are affected by CVE-2017-18489.
CVE-2017-18489 is a Cross-Site Scripting (XSS) vulnerability.
Yes, if you are using an outdated version of the contact-form-7-sms-addon plugin, your WordPress site is at risk of XSS attacks.