Vulnerability Description
The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mooveagency | Contact Form Check Tester | <= 1.0.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/e2990a7a-d4f0-424e-b01d-ecf67cf9c9f3ExploitThird Party Advisory
- https://wpscan.com/vulnerability/e2990a7a-d4f0-424e-b01d-ecf67cf9c9f3ExploitThird Party Advisory
FAQ
What is CVE-2021-24247?
CVE-2021-24247 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as s...
How severe is CVE-2021-24247?
CVE-2021-24247 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24247?
Check the references section above for vendor advisories and patch information. Affected products include: Mooveagency Contact Form Check Tester.