Rocklobster

Contact Form 7

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 16.04.2025 05:23:00
  • Zuletzt bearbeitet 08.07.2025 18:13:23

The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unau...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 27.06.2024 06:15:14
  • Zuletzt bearbeitet 21.11.2024 09:43:24

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

  • EPSS 56.29%
  • Veröffentlicht 13.03.2024 22:15:12
  • Zuletzt bearbeitet 17.01.2025 19:57:07

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for un...

  • EPSS 0.23%
  • Veröffentlicht 11.01.2024 05:15:09
  • Zuletzt bearbeitet 21.11.2024 08:44:15

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missing validation ...

  • EPSS 4.1%
  • Veröffentlicht 01.12.2023 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:43:53

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and incl...

  • EPSS 0.11%
  • Veröffentlicht 05.04.2021 19:15:15
  • Zuletzt bearbeitet 21.11.2024 05:52:29

Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfu...

  • EPSS 90.11%
  • Veröffentlicht 17.12.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:23

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

  • EPSS 0.34%
  • Veröffentlicht 22.08.2019 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:02:36

The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.

  • EPSS 1.38%
  • Veröffentlicht 14.03.2014 10:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.