The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.
2023-06-12T18:15:10.167
2024-11-21T07:59:09.650
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | codepeople | contact_form_email | < 1.3.38 | Yes |