Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
themefic ultimate addons for contact form 7 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-30493
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions.
Themefic Ultimate Addons For Contact Form 7
8.1
CVSSv3
CVE-2023-30495
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Ultimate Addons for Contact Form 7.This issue affects Ultimate Addons for Contact Form 7: from n/a up to and including 3.1.23.
Themefic Ultimate Addons For Contact Form 7
6.1
CVSSv3
CVE-2023-49766
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Stored XSS.This issue affects Ultimate Addons for Contact Form 7: from n/a up to and including 3.2.0.
Themefic Ultimate Addons For Contact Form 7
4.8
CVSSv3
CVE-2023-2802
The Ultimate Addons for Contact Form 7 WordPress plugin prior to 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f...
Themefic Ultimate Addons For Contact Form 7
6.1
CVSSv3
CVE-2023-2803
The Ultimate Addons for Contact Form 7 WordPress plugin prior to 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Themefic Ultimate Addons For Contact Form 7
6.5
CVSSv3
CVE-2023-1615
The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any authorization level to append additional SQL queries int...
Themefic Ultimate Addons For Contact Form 7
9.8
CVSSv3
CVE-2022-47586
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.
Themefic Ultimate Addons For Contact Form 7
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started