Unauthenticated Attackers can Inject Arbitrary Web Scripts through Reflected Cross-Site Scripting in Constant Contact Forms
CVE-2024-9614
6.1MEDIUM
What is CVE-2024-9614?
The Constant Contact Forms by MailMunch plugin for WordPress exposes a vulnerability due to improper handling of URL parameters using the add_query_arg function. This flaw allows unauthenticated attackers to execute arbitrary web scripts on affected pages. By tricking users into clicking manipulated links, attackers can exploit this vulnerability to gain unauthorized access to sensitive information. All versions leading up to 2.1.2 are susceptible, making it crucial for users to assess and update their plugins promptly to mitigate potential threats.