QID 730807

Date Published: 2023-05-22

QID 730807: WordPress Plugin Contact Form by Supsystic Reflected Cross-Site Scripting (XSS) Vulnerability

Simple and powerful Contact Form Builder by Supsystic with drag-and-drop editor.

CVE-2021-24276: The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue.

Affected Versions:
Contact Form by Supsystic WordPress plugin prior to 1.7.15

QID Detection Logic(Unauthenticated):
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Contact Form by Supsystic WordPress plugin.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary JavaScript code on the target system.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to install Contact Form by Supsystic plugin version 1.7.15 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730807

    Software Advisories
    Advisory ID Software Component Link
    Contact Form by Supsystic Release Notes URL Logo wordpress.org/plugins/contact-form-by-supsystic/#developers