WordPress Contact Form to Email 1.3.24 Stored XSS
Vulnerability Description
Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47926
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mohammed Aadhil Ashfaq
Affected Vendor
Form2Email
View all reports →