Cross-site Scripting Vulnerability in Contact Form DB Plugin for WordPress
CVE-2015-2040
Currently unrated
Summary
The Contact Form DB plugin for WordPress version 2.8.26 is vulnerable to cross-site scripting (XSS) attacks. This vulnerability enables attackers to inject arbitrary web scripts or HTML through the 'submit_time' parameter on the CF7DBPluginSubmissions page in the WordPress admin interface (wp-admin/admin.php). Exploiting this security flaw can allow unauthorized users to compromise the integrity of the site, potentially leading to data theft or other malicious actions.
References
Timeline
Vulnerability published
Vulnerability Reserved