cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontact-form-7-datepicker-fix contact-form-7-datepicker-fix

Direction: ascending
Jun 07, 2024

Contact Form 7 IE DatePicker and Number Spinner Fix # CVE-2020-11516

CVE, Research URL

CVE-2020-11516

Date
Apr 07, 2020
Research Description
Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a contact form, the JavaScript will be executed in their browser, which can then be used to create new administrative users or perform other actions using the administrator's session.
Affected versions
max 2.6.0.
Status
vulnerable