Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Contact Form With Captcha Project Subscribe
Filtered by product Contact Form With Captcha
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42358 1 Contact Form With Captcha Project 1 Contact Form With Captcha 2021-12-01 6.8 MEDIUM 8.8 HIGH
The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.