PT-2026-103138 · WordPress · Cf7 Views
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CF7 Views – Complete Entry Management for Contact Form 7 versions prior to 3.2.6
Description
Cross Site Scripting (XSS) allows users with contributor privileges to execute malicious scripts in the browser of other users. This occurs due to insufficient sanitization of user-supplied input.
Recommendations
Update CF7 Views – Complete Entry Management for Contact Form 7 to version 3.2.6 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cf7 Views