CVE-2021-25079

Publication date

2022-01-24 08:01:27

Family

WPScan

State

PUBLISHED

Description

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page