CVE-2020-11516

Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a contact form, the JavaScript will be executed in their browser, which can then be used to create new administrative users or perform other actions using the administrator's session.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:contact-form-7-datepicker_project:contact-form-7-datepicker:*:*:*:*:*:wordpress:*:*

Information

Published : 2020-04-07 10:15

Updated : 2020-04-10 10:01


NVD link : CVE-2020-11516

Mitre link : CVE-2020-11516


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

contact-form-7-datepicker_project

  • contact-form-7-datepicker