Cross-Site Scripting Vulnerability in Clean and Simple Contact Form Plugin for WordPress
CVE-2014-8955
Currently unrated
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 November 2014
What is CVE-2014-8955?
The Clean and Simple Contact Form plugin for WordPress is vulnerable to cross-site scripting (XSS), which can be exploited by remote attackers. Through manipulation of the cscf[name] parameter during form submissions, attackers may inject arbitrary web scripts or HTML, potentially compromising user data and the integrity of the website. This vulnerability targets users running version 4.4.0 and earlier, emphasizing the need for immediate updates to protect against possible malicious intrusions.