cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontact-form-7-datepicker-fix contact-form-7-datepicker-fix

Direction: ascending
Jun 07, 2024

Contact Form 7 IE DatePicker and Number Spinner Fix # CVE-2020-11516

CVE, Research URL

CVE-2020-11516

Date
Apr 07, 2020
Research Description
Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a contact form, the JavaScript will be executed in their browser, which can then be used to create new administrative users or perform other actions using the administrator's session.
Affected versions
max 2.6.0.
Status
vulnerable
Jun 13, 2026

Contact Form 7 IE DatePicker and Number Spinner Fix # 02c690f19974a88d0c8d24171a85c979710c0152

Date
Apr 02, 2020
Research Description
Contact Form 7 IE DatePicker and Number Spinner Fix [contact-form-7-datepicker-fix] <= 2.6.0 (unfixed) WordPress Contact Form 7 Datepicker plugin <= 2.6.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WordFence in WordPress Contact Form 7 Datepicker plugin (versions <= 2.6.0).
Affected versions
max 2.6.0.
Status
vulnerable