vendor:
CF7 International SMS Integration
by:
Milad karimi
8.8
CVSS
HIGH
Cross Site Scripting (XSS)
79
CWE
Product Name: CF7 International SMS Integration
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE:
CPE: a:wordpress:cf7-international-sms-integration
Platforms Tested: Windows 11
2022
WordPress Plugin International Sms For Contact Form 7 Integration V1.2 – Cross Site Scripting (XSS)
This plugin creates a cf7-international-sms-integration from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.
Mitigation:
Upgrade to version 1.3 or later.