CVE-2024-12587

The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:edmonparker:contact_form_master:*:*:*:*:*:wordpress:*:*

History

17 May 2025, 02:35

Type Values Removed Values Added
CPE cpe:2.3:a:edmonparker:contact_form_master:*:*:*:*:*:wordpress:*:*
CWE CWE-79
References () https://wpscan.com/vulnerability/7cb040f5-d154-48ea-a54e-80451054bad8/ - () https://wpscan.com/vulnerability/7cb040f5-d154-48ea-a54e-80451054bad8/ - Exploit, Third Party Advisory
First Time Edmonparker
Edmonparker contact Form Master

13 Jan 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) El complemento Contact Form Master de WordPress hasta la versión 1.0.7 no desinfecta ni escapa un parámetro antes de mostrarlo nuevamente en la página, lo que genera un error de Cross Site Scripting Reflejado que podría usarse contra usuarios con privilegios elevados, como el administrador.

11 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 06:15

Updated : 2025-05-17 02:35


NVD link : CVE-2024-12587

Mitre link : CVE-2024-12587

CVE.ORG link : CVE-2024-12587


JSON object : View

Products Affected

edmonparker

  • contact_form_master
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')