CVE-2021-24276: Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24276?
CVE-2021-24276 is a vulnerability in the Contact Form by Supsystic WordPress plugin before version 1.7.15, which allows for a reflected Cross-Site Scripting (XSS) attack.
What is the severity of CVE-2021-24276?
CVE-2021-24276 has a severity rating of 6.1 (Medium).
How does CVE-2021-24276 affect the Contact Form by Supsystic WordPress plugin?
CVE-2021-24276 affects the Contact Form by Supsystic WordPress plugin before version 1.7.15 by allowing an attacker to exploit a reflected Cross-Site Scripting vulnerability.
How can I fix CVE-2021-24276?
To fix CVE-2021-24276, it is recommended to update the Contact Form by Supsystic WordPress plugin to version 1.7.15 or later.
Is there any additional information about CVE-2021-24276?
Additional information about CVE-2021-24276 can be found at the following references: [Link 1](http://packetstormsecurity.com/files/164308/WordPress-Contact-Form-1.7.14-Cross-Site-Scripting.html), [Link 2](https://wpscan.com/vulnerability/1301123c-5e63-432a-ab90-3221ca532d9c).