Skip to content

Known CVE

Contact Form Entries < 1.2.4 - Cross-Site Scripting

The plugin does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

CVE-2021-25079

Medium2021CVSS 6.1CWE-79

cve2021 · wordpress · wp-plugin · wpscan · authenticated · contact-form-entries · xss · crmperks

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website