Stored XSS Vulnerability in Contact Form Plugin for WordPress by WPVULNDB
CVE-2014-7238
6.1MEDIUM
What is CVE-2014-7238?
The Contact Form Integrated With Google Maps plugin for WordPress versions 1.0 to 2.4 is vulnerable to stored cross-site scripting (XSS). This flaw allows attackers to inject malicious scripts that could execute when a victim interacts with the compromised form submission feature. Given its potential exploitation, site administrators using this plugin should apply necessary patches or updates to safeguard against unauthorized script execution.