Known CVE
Contact Form Entries < 1.2.4 - Cross-Site Scripting
The plugin does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
CVE-2021-25079
Medium2021CVSS 6.1CWE-79
cve2021 · wordpress · wp-plugin · wpscan · authenticated · contact-form-entries · xss · crmperks
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website