CVE-2021-24159
Contact Form 7 に報告された脆弱性
高深刻度
8.8CVSS 3.1
未公表修正されたバージョン
0.6%30日以内に悪用される確率
概要
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.
影響を受けるバージョン
- 3.1.9 以下
対処方法
修正版が公表されていません。最新版への更新、無効化、または代替プラグインへの移行を検討してください。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- https://wpscan.com/vulnerability/363182f1-9fda-4363-8f6a-be37c4c07aa9
- https://www.wordfence.com/blog/2021/02/unpatched-vulnerability-50000-wp-sites-must-find-alternative-for-contact-form-7-style/
- https://wpscan.com/vulnerability/363182f1-9fda-4363-8f6a-be37c4c07aa9
- https://www.wordfence.com/blog/2021/02/unpatched-vulnerability-50000-wp-sites-must-find-alternative-for-contact-form-7-style/