CVE-2024-48021: WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on contact-form-7-paypal-add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through <= 2.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48021?
CVE-2024-48021 has been classified as a medium severity vulnerability due to the potential for reflected XSS attacks.
How do I fix CVE-2024-48021?
To fix CVE-2024-48021, update the Contact Form 7 – PayPal & Stripe Add-on plugin to a version later than 2.3.
What type of vulnerability is CVE-2024-48021?
CVE-2024-48021 is a reflected Cross-Site Scripting (XSS) vulnerability.
Which software versions are affected by CVE-2024-48021?
CVE-2024-48021 affects the Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin versions up to 2.3.
Can CVE-2024-48021 lead to data theft?
Yes, CVE-2024-48021 can potentially lead to data theft through malicious scripts if exploited.