What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 versions.
Explanation of Vulnerability in Simple Terms
Popup Contact Form versions 7.1 and earlier contain a cross-site scripting (XSS) vulnerability in form handling. An authenticated administrator with high privileges can inject malicious scripts that execute in other users' browsers when they interact with the form. The vulnerability requires user interaction and affects the integrity and confidentiality of site data.
What an attacker can do
Inject malicious scripts that run in visitors' browsers when they view or submit the contact form.
Potential impact on your site
Administrators with high privileges could inject scripts affecting form submissions and visitor data; requires user interaction to trigger.
Conditions required to exploit
Attacker must have high-level admin privileges and trick a user into visiting a crafted page or link.
Key dates
External resources
Related vulnerabilities