Cross-Site Scripting Vulnerability in Clean and Simple Contact Form Plugin for WordPress
CVE-2014-8955

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
17 November 2014

What is CVE-2014-8955?

The Clean and Simple Contact Form plugin for WordPress is vulnerable to cross-site scripting (XSS), which can be exploited by remote attackers. Through manipulation of the cscf[name] parameter during form submissions, attackers may inject arbitrary web scripts or HTML, potentially compromising user data and the integrity of the website. This vulnerability targets users running version 4.4.0 and earlier, emphasizing the need for immediate updates to protect against possible malicious intrusions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.