S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 14, 2024

CVE-2017-18492 Scanner

CVE-2017-18492 scanner - Cross-Site Scripting (XSS) vulnerability in Contact Form plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18492
6.1
CVSS

The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Contact Form plugin for WordPress is a widely-used plugin that allows website owners to create customized forms for their visitors to fill out. These forms can be used for a variety of purposes, such as collecting feedback, gathering user information, or processing orders. The plugin is popular among WordPress users due to its easy-to-use interface and vast array of customization options.

One of the most concerning vulnerabilities that has been discovered in the Contact Form plugin is CVE-2017-18492. This vulnerability allows attackers to input malicious code into the Contact Form, which can then be executed when a user submits the form. Essentially, this means that if a website is using an outdated version of the plugin, an attacker could potentially execute code on that site without the website owner's knowledge.

If this vulnerability is exploited, it can lead to a variety of negative consequences. For example, an attacker could steal sensitive information such as login credentials or credit card numbers from visitors who submit the form. Additionally, an attacker could use the vulnerability to inject malware onto the website, infecting the devices of any visitors who access the site.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. By utilizing this platform, website owners can gain access to a wealth of information on potential vulnerabilities and steps they can take to protect themselves and their visitors. With the increasing prevalence of cyber attacks, it's more important than ever for website owners to take proactive steps to secure their online presence.

 

REFERENCES

Solution Advice

There are several precautions that website owners can take to protect themselves and their visitors against this vulnerability. These include:

  • Keeping the Contact Form plugin up-to-date to ensure that the latest security patches are in place.
  • Enabling web application firewalls (WAFs) to monitor incoming traffic for malicious activity.
  • Using content security policies (CSPs) to block any attempts to execute scripts from untrusted sources.
  • Disabling the use of HTML in form submissions, which can help prevent the execution of malicious code.
  • Conducting regular security audits to identify and address any vulnerabilities in the website's code and plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18492 scanner - Cross-Site Scripting (XSS) vulnerability in Contact Form plugin for WordPress | S4E