Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total22
Critical1
High4
Medium16
Reset
Showing 21-22 of 22 records
Threat Entry Updated 2024-11-21

CVE-2021-24159 - Contact Form 7 Plugin

Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.

PLUGIN Contact Form 7

CVE-2021-24159

HIGH CVSS 8.8 2021-04-05
Scroll to top