CVE-2021-25079: Contact Form Entries < 1.2.4 - Reflected Cross-Site Scripting
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as formid, status, enddate, order, orderby and search before outputting them back in the admin page
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-25079.
What is the severity of CVE-2021-25079?
The severity of CVE-2021-25079 is medium (6.1).
What is the affected software for CVE-2021-25079?
The affected software for CVE-2021-25079 is the Contact Form Entries WordPress plugin before version 1.2.4.
What are the parameters that are not properly sanitized and escaped in the Contact Form Entries WordPress plugin before version 1.2.4?
The parameters that are not properly sanitized and escaped in the Contact Form Entries WordPress plugin before version 1.2.4 are form_id, status, end_date, order, orderby, and search.
Are there any references available for CVE-2021-25079?
Yes, you can find references for CVE-2021-25079 at the following links: [First Reference](https://plugins.trac.wordpress.org/changeset/2629442), [Second Reference](https://wpscan.com/vulnerability/c3d49271-9656-4428-8357-0d1d77b7fc63)