QID 730807
Date Published: 2023-05-22
QID 730807: WordPress Plugin Contact Form by Supsystic Reflected Cross-Site Scripting (XSS) Vulnerability
Simple and powerful Contact Form Builder by Supsystic with drag-and-drop editor.
CVE-2021-24276: The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue.
Affected Versions:
Contact Form by Supsystic WordPress plugin prior to 1.7.15
QID Detection Logic(Unauthenticated):
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Contact Form by Supsystic WordPress plugin.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary JavaScript code on the target system.
Solution
Customers are advised to install Contact Form by Supsystic plugin version 1.7.15 or later version to remediate this vulnerability.
Vendor References
- Contact Form by Supsystic Release Notes -
wordpress.org/plugins/contact-form-by-supsystic/#developers
CVEs related to QID 730807
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Contact Form by Supsystic Release Notes |
|