CVE-2024-5809: WP Ajax Contact Form <= 2.2.2 - Reflected Cross-Site Scripting
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5809?
CVE-2024-5809 has a high severity rating due to its ability to lead to Reflected Cross-Site Scripting attacks.
How do I fix CVE-2024-5809?
To fix CVE-2024-5809, update the WP Ajax Contact Form plugin to a version later than 2.2.2 where the vulnerability has been addressed.
Who is affected by CVE-2024-5809?
CVE-2024-5809 affects users of the WP Ajax Contact Form plugin for WordPress versions up to and including 2.2.2.
What type of vulnerability is CVE-2024-5809?
CVE-2024-5809 is a Reflected Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-5809 be exploited remotely?
Yes, CVE-2024-5809 can be exploited remotely, potentially impacting admin users through malicious requests.