QID 150839

Date Published: 2024-03-26

QID 150839: WordPress Contact Form 7 Plugin: Reflected Cross-Site Scripting (XSS) Vulnerability (CVE-2024-2242)

Contact Form 7 is a WordPress plugin which allows users to customize, manage multiple contact forms along with mail facility.

Affected version of Contact Form 7 plugin is vulnerable to Reflected Cross-Site Scripting (XSS) via the 'active-tab' parameter due to insufficient input sanitization and output escaping.

Affected Versions:
Contact Form 7 prior to version 5.9.2

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Contact Form 7 plugin running on the target WordPress application.

Successful exploitation of this vulnerability could allow an unauthenticated attacker to inject arbitrary JavaScript code in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade Contact Form 7 to version 5.9.2 or later to remediate this vulnerability. For more information pertaining to this vulnerability please refer Contact Form 7 release notes and Wordfence Advisory.
    Vendor References

    CVEs related to QID 150839

    Software Advisories
    Advisory ID Software Component Link
    Contact Form 7 URL Logo contactform7.com/2024/03/12/contact-form-7-592/