What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.
Explanation of Vulnerability in Simple Terms
The Admin side data storage component for Contact Form 7 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts. An attacker can craft a malicious link or page that, when visited by a site administrator, executes arbitrary JavaScript in their browser session. This can lead to unauthorized actions, data theft, or account compromise within the WordPress admin panel.
What an attacker can do
Execute JavaScript code in an admin's browser to steal credentials, modify site content, or perform unauthorized admin actions.
Potential impact on your site
Admins visiting malicious links could have their sessions hijacked or site settings altered without their knowledge.
Conditions required to exploit
An admin must visit a malicious link or page crafted by the attacker; no authentication required from the attacker.
Key dates
External resources
Related vulnerabilities