CVE-2021-25080: Contact Form Entries < 1.1.7 - Unauthenticated Stored Cross-Site Scripting
Published Jan 24, 2022
·Updated
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
Affected Software
1 affected component
crmperks Contact Form Entries Wordpress<1.1.7
Remediation
Patch Available
Event History
Jan 24, 2022
CVE Published
via MITRE·08:01 AM
Data Sourced
via MITRE·08:01 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-25080.
2
What is the severity level of CVE-2021-25080?
The severity level of CVE-2021-25080 is medium.
3
How can an attacker exploit CVE-2021-25080?
An attacker can exploit CVE-2021-25080 by performing Cross-Site Scripting (XSS) attacks against logged in admins viewing the created entry.
4
Is authentication required for an attacker to exploit CVE-2021-25080?
No, authentication is not required for an attacker to exploit CVE-2021-25080.
5
Is there a fix available for CVE-2021-25080?
Yes, the Contact Form Entries WordPress plugin has released version 1.1.7 which fixes the vulnerability.