CVE-2021-24247: Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24247?
The severity of CVE-2021-24247 is medium with a CVSS score of 5.4.
How does CVE-2021-24247 affect the Contact Form Check Tester WordPress plugin?
CVE-2021-24247 allows any registered user, such as a subscriber, to leave an XSS payload in the plugin settings, which can be triggered by any visitor.
Can all registered users in the dashboard see the settings of Contact Form Check Tester plugin?
Yes, all registered users in the dashboard can see the settings of the Contact Form Check Tester plugin.
Are the settings of Contact Form Check Tester plugin lacking sanitization?
Yes, the settings of the Contact Form Check Tester plugin lack sanitization.
How do I fix CVE-2021-24247 in Contact Form Check Tester plugin?
To fix CVE-2021-24247 in the Contact Form Check Tester plugin, it's recommended to update the plugin to the latest version available.