S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 29, 2024

CVE-2021-25079 Scanner

CVE-2021-25079 scanner - XSS vulnerability in Contact Form Entries

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25079
6.1
CVSS

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Contact Form Entries – Contact Form 7, WPforms and more
AFFECTED< 1.2.4SAFE ✓≥ 1.2.4
Updated Aug 21, 2026View on NVD →
Detail

Contact Form Entries is a WordPress plugin designed to capture and manage submissions from contact forms on WordPress websites. It's used by website owners and administrators to easily store, view, and manage data submitted by visitors through contact forms. This plugin supports various contact form plugins, making it versatile for different types of WordPress sites. It's especially useful for businesses and bloggers who need to organize communication from their audience efficiently. The primary purpose is to enhance user engagement and streamline the management of form submissions.

The vulnerability specifically affects the administrative interface of the Contact Form Entries plugin. Malicious scripts can be injected through the manipulation of parameters like form_id and end_date in the URL. When an administrator accesses the entries page to view form submissions, the malicious code is executed within their browser. This flaw highlights the importance of input validation and output encoding in web applications to prevent XSS attacks. Attackers exploit this vulnerability by crafting malicious URLs that execute arbitrary JavaScript in the context of the logged-in user's session.

If exploited, this XSS vulnerability could lead to several adverse effects, including the theft of cookies and session tokens, which could allow attackers to hijack the administrator's session. It could also enable the attacker to redirect the administrator to malicious websites, manipulate the content of the web page to display false information, or even gain control over the affected website. The impact of such attacks can extend beyond the compromised website, affecting users' trust and the site's reputation.

S4E platform offers comprehensive scanning solutions that can identify and help remediate vulnerabilities like CVE-2021-25079. By becoming a member, users gain access to advanced scanning technology that detects security flaws in real-time, ensuring that their websites remain safe from potential attacks. The platform also provides detailed reports and remediation guidance, empowering users to fix vulnerabilities efficiently. With S4E, website owners can maintain a secure online presence, protect sensitive data, and build trust with their audience.

 

References

Solution Advice
  1. Immediately update the Contact Form Entries plugin to version 1.2.4 or higher.
  2. Regularly update all WordPress plugins and themes to their latest versions to mitigate vulnerabilities.
  3. Utilize content security policies (CSP) to reduce the risk of XSS attacks.
  4. Conduct periodic security audits of your WordPress site to identify and address potential security issues.
  5. Educate users with administrative access about the dangers of phishing and malicious emails to prevent social engineering attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-25079 scanner - XSS vulnerability in Contact Form Entries | S4E