Reflected XSS Vulnerability in Table & Contact Form 7 Database
CVE-2024-29110
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 March 2024
What is CVE-2024-29110?
The vulnerability identified pertains to improper neutralization of input during web page generation, commonly referred to as Cross-site Scripting (XSS). This security flaw allows an attacker to exploit the Pauple Table & Contact Form 7 Database by crafting malicious scripts that could be executed within the context of the user's browser. As a result, this vulnerability poses potential risks such as session hijacking, data manipulation, and unauthorized actions. Affected users should apply necessary patches and updates to mitigate the risks associated with versions up to 1.0.27.
Affected Version(s)
Table & Contact Form 7 Database β Tablesome <= 1.0.27