Описание
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.
Ссылки
- Third Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.0 (исключая)
cpe:2.3:a:redirection-for-contact-form7:redirection_for_contact_form_7:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 66%
0.00516
Низкий
7.5 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-284
CWE-74
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.
EPSS
Процентиль: 66%
0.00516
Низкий
7.5 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-284
CWE-74