WordPress Contact Form 7 Plugin Vulnerability

WordPress Contact Form 7 plugin version 5.9 is vulnerable to Cross Site Scripting (XSS) – High severity.

The issue will be resolved by Resolve by 20 March 2024. 

Asaf Mozes identified and alerted to a Cross Site Scripting (XSS) vulnerability present in the WordPress Contact Form 7 Plugin. This flaw could enable a malicious individual to inject harmful scripts, such as redirects, advertisements, and various HTML payloads into your website, triggering execution when visitors access your site. The issue has been addressed in version 5.9.2.

Solution:

Update the WordPress Contact Form 7 plugin to the latest available version (at least 5.9.2).

WordPress Elementor Website Builder Plugin <= 3.18.3 is vulnerable to Cross Site Scripting (XSS)

WordPress Elementor plugin <= 3.18.3 – Authenticated Stored Cross-Site Scripting via get_image_alt vulnerability

Wesley (wcraft) identified and brought to attention a Cross Site Scripting (XSS) vulnerability present in the WordPress Elementor Website Builder Plugin. Exploiting this flaw could empower a malicious actor to insert harmful scripts, such as redirects, advertisements, and various HTML payloads, into your website. These scripts would then be executed when visitors access your site. The identified vulnerability has been addressed and resolved in version 3.19.0.

The Elementor Website Builder, a WordPress plugin that goes beyond conventional page building, exhibits a vulnerability to Reflected Cross-Site Scripting through the $instance[alt] parameter within the get_image_alt function. This vulnerability exists in all versions up to and including 3.18.3, stemming from inadequate input sanitization and output escaping. Consequently, authenticated attackers with contributor access or higher could potentially inject arbitrary web scripts into pages. The execution of these scripts relies on successfully deceiving a user into taking actions like clicking on a link.
WordPress Elementor vulnerability

Solution

Update the WordPress Elementor Website Builder plugin to the latest available version (at least 3.19.0). To get regular updates and more features, upgrade to Elementor Pro.

Not sure how to update your plugins?

We are here to do this on a regular basis. Explore our WordPress Website Maintenance service to know we will ease the process for you.