WordPress Contact Form 7 漏洞列表
共找到 5 个与 WordPress Contact Form 7 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2020-12800: WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution POC
WordPress Contact Form 7 before 1.3.3.3 allows unrestricted file upload and remote code execution by setting supported_type to php% and uploading a .php% file. -
CVE-2021-24278: WordPress Contact Form 7 <2.3.4 - Arbitrary Nonce Generation POC
WordPress Contact Form 7 before version 2.3.4 allows unauthenticated users to use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function. -
CVE-2021-25063: WordPress Contact Form 7 Skins <=2.5.0 - Cross-Site Scripting POC
WordPress Contact Form 7 Skins plugin 2.5.0 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the tab parameter before outputting it back in an admin page. -
CVE-2022-0595: WordPress Contact Form 7 <1.3.6.3 - Stored Cross-Site Scripting POC
WordPress Contact Form 7 before 1.3.6.3 contains an unauthenticated stored cross-site scripting vulnerability in the Drag and Drop Multiple File Upload plugin. SVG files can be uploaded by default via the dnd_codedropz_upload AJAX action. -
CVE-2022-2187: WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scripting POC
WordPress Contact Form 7 Captcha plugin before 0.1.2 contains a reflected cross-site scripting vulnerability. It does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute.