CVE-2017-18491: XSS
Published Aug 13, 2019
·Updated
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
Affected Software
1 affected component
Bestwebsoft Contact Form Wordpress<4.0.6
Event History
Aug 13, 2019
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the contact-form-plugin for WordPress?
The vulnerability ID for the contact-form-plugin for WordPress is CVE-2017-18491.
2
What is the severity of CVE-2017-18491?
The severity of CVE-2017-18491 is medium.
3
What is the affected software for CVE-2017-18491?
The affected software for CVE-2017-18491 is the contact-form-plugin plugin before version 4.0.6 for WordPress.
4
What is the Common Weakness Enumeration (CWE) for CVE-2017-18491?
The Common Weakness Enumeration (CWE) for CVE-2017-18491 is CWE-79.
5
How do I fix the XSS issues in the contact-form-plugin for WordPress?
To fix the XSS issues in the contact-form-plugin for WordPress, you should upgrade to version 4.0.6 or later of the plugin.