Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin 2.8.26 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit_time parameter in the CF7DBPluginSubmissions page to wp-admin/admin.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cfdbplugin | Contact Form Db | 2.8.26 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/130311/WordPress-Contact-Form-DB-2.8.26-CroExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100818
- http://packetstormsecurity.com/files/130311/WordPress-Contact-Form-DB-2.8.26-CroExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100818
FAQ
What is CVE-2015-2040?
CVE-2015-2040 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin 2.8.26 for WordPress allows remote attackers to inject arbitrary web script o...
How severe is CVE-2015-2040?
CVE-2015-2040 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2040?
Check the references section above for vendor advisories and patch information. Affected products include: Cfdbplugin Contact Form Db.