WordPress Contact Form 7是WordPress基金会的一款WordPress表单插件动态文本扩展工具。 WordPress Contact Form 7 1.5.3之前版本存在跨站脚本漏洞,该漏洞源于未正确清理和转义一个参数,导致反射型跨站脚本攻击,可能被用于针对高权限用户如管理员。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Database for Contact Form 7, WPforms, Elementor forms | < 1.5.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Database for Contact Form 7, WPforms, Elementor forms | 0 ~ 1.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14545 | TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Res | |
| CVE-2026-14924 | Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification | |
| CVE-2026-14821 | Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion | |
| CVE-2026-14819 | Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move | |
| CVE-2026-14926 | FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR |
No comments yet