The Contact Form 7 Captcha WordPress plugin prior to 0.0.9 does not have any CSRF check in place when saving its settings, allowing malicious user to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
contact form 7 captcha project contact form 7 captcha |