CVE-2022-25601
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
- Affected products
- Contact Form
- Plugin-planet Contact Form X
- < 2.4.1
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.0% (61th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-03-11
Fix
Update to 2.4.1 or higher version.
CVE-2022-25601 at NVD
1 known exploit for CVE-2022-25601
Proof-of-concept code and exploit modules indexed by Sploitus