First published: Fri Mar 11 2022(Updated: )
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
plugin-planet Contact Form X WordPress | <2.4.1 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 |
Update to 2.4.1 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25601 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Contact Form X WordPress plugin (versions <= 2.4).
The severity of CVE-2022-25601 is medium with a severity value of 6.1.
Versions <= 2.4.1 of the Contact Form X WordPress plugin, Fedora 34, Fedora 35, and Fedora 36 are affected by CVE-2022-25601.
To fix CVE-2022-25601, update the Contact Form X WordPress plugin to a version higher than 2.4.1 or apply the necessary patches provided by the plugin developer.
The CWE ID of CVE-2022-25601 is 79, which refers to Improper Neutralization of Input During Web Page Generation (Cross-site Scripting).