CVE-2021-36885: WordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-36885?
CVE-2021-36885 refers to an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in the Contact Form 7 Database Addon - CFDB7 WordPress plugin (versions <= 1.2.6.1).
How severe is CVE-2021-36885?
CVE-2021-36885 has a severity level of medium (6.1).
Which software versions are affected by CVE-2021-36885?
Versions up to and including 1.2.6.1 of the Ciphercoin Contact Form 7 Database Addon WordPress plugin are affected by CVE-2021-36885.
How can CVE-2021-36885 be fixed?
To fix CVE-2021-36885, update the Contact Form 7 Database Addon - CFDB7 WordPress plugin to a version beyond 1.2.6.1.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-36885?
The CWE ID for CVE-2021-36885 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').