WordPress Contact Form 7 Skins plugin 2.5.0 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the tab parameter before outputting it back in an admin page.
id: CVE-2021-25063
info:
name: WordPress Contact Form 7 Skins <=2.5.0 - Cross-Site Scripting
au
...