S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 14, 2024

CVE-2017-18490 Scanner

CVE-2017-18490 scanner - Cross-Site Scripting (XSS) vulnerability in Contact Form Multi plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18490
6.1
CVSS

The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Contact Form Multi is a popular plugin for WordPress that allows users to create multiple contact forms on their website. With this plugin, website administrators can easily add forms to their pages and posts, and customize them according to their specific needs. The plugin also provides users with a range of options for managing and organizing the data collected from these forms, making it a versatile and useful tool for businesses and individuals alike.

CVE-2017-18490 is a vulnerability that was recently detected in the Contact Form Multi plugin. This vulnerability allows an attacker to inject malicious code into the plugin, which can then be executed on the victim's website. Specifically, the vulnerability exists in the plugin's handling of input data, which can be manipulated by an attacker in order to execute cross-site scripting (XSS) attacks.

When exploited, this vulnerability can lead to a range of negative outcomes for website owners and their users. For example, an attacker could compromise the security of the website by stealing user data or installing malware. They could also hijack the website's traffic, redirecting users to malicious sites with the intent of stealing their personal information or infecting their devices with malware.

In conclusion, the CVE-2017-18490 vulnerability in the Contact Form Multi plugin is a serious threat that website owners should take steps to protect against. However, with the right precautions and tools in place, it is possible to mitigate the risk of an attack and keep users' data and privacy safe. For those looking for more information on how to protect their digital assets, s4e.io offers a range of pro features that can help identify and resolve vulnerabilities quickly and easily.

 

REFERENCES

Solution Advice

In order to protect against this vulnerability, website owners should take a number of precautions, including the following:

  • Always keep the Contact Form Multi plugin up to date with the latest security patches and software updates.
  • Use strong passwords and two-factor authentication to protect against unauthorized access to the website's administrative accounts.
  • Monitor the website for suspicious activity and unusual traffic patterns, which may indicate a hack or attack in progress.
  • Use a web application firewall to block known attacks and vulnerabilities, and to detect and respond to new threats as they emerge.
  • Regularly back up website data and files, so that in the event of a compromise, the website can be restored to its previous state.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18490 scanner - Cross-Site Scripting (XSS) vulnerability in Contact Form Multi plugin for WordPress | S4E