CVE-2023-24420 HIGH

CVE-2023-24420: WordPress Admin side data storage for Contact Form 7 Plugin <= 1.1.1 is vulnerable to Cross Site Scripting (XSS)

Vendor Zestard Technologies
Product Admin side data storage for Contact Form 7
Weakness CWE-79 · XSS
Published June 15, 2023
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The Admin side data storage component for Contact Form 7 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts. An attacker can craft a malicious link or page that, when visited by a site administrator, executes arbitrary JavaScript in their browser session. This can lead to unauthorized actions, data theft, or account compromise within the WordPress admin panel.

What an attacker can do

03Attacker Capabilities

Execute JavaScript code in an admin's browser to steal credentials, modify site content, or perform unauthorized admin actions.

Potential impact on your site

04Site Impact

Admins visiting malicious links could have their sessions hijacked or site settings altered without their knowledge.

Conditions required to exploit

05Prerequisites

An admin must visit a malicious link or page crafted by the attacker; no authentication required from the attacker.

Key dates

06Disclosure timeline

June 15, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE