mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 10:22:48 +02:00
896 B
896 B
CVE-2021-25063
Description
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
POC
Reference
- https://wpscan.com/vulnerability/e2185887-3e53-4089-aa3f-981c944ee0bb
- https://wpscan.com/vulnerability/e2185887-3e53-4089-aa3f-981c944ee0bb