Cross-site Scripting Vulnerability in Contact Form DB Plugin for WordPress
CVE-2015-2040

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 February 2015

Summary

The Contact Form DB plugin for WordPress version 2.8.26 is vulnerable to cross-site scripting (XSS) attacks. This vulnerability enables attackers to inject arbitrary web scripts or HTML through the 'submit_time' parameter on the CF7DBPluginSubmissions page in the WordPress admin interface (wp-admin/admin.php). Exploiting this security flaw can allow unauthorized users to compromise the integrity of the site, potentially leading to data theft or other malicious actions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.