Contact Form Entries < 1.1.7 - Unauthenticated Stored Cross-Site Scripting
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 84%
exploitation probability
84%top 1% of all CVEs
observed exploitation
nono source reports it
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
Affected products
Unknown · Contact Form Entries – Contact Form 7, WPforms and more