WordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2021-36885
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 December 2021
What is CVE-2021-36885?
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).
Affected Version(s)
Contact Form 7 Database Addon – CFDB7 (WordPress plugin) <= 1.2.6.1 <= 1.2.6.1