CyberSec.Space Logo
Back to CVE Browser

CVE-2014-7240

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0170%
EPSS Percentile40.44th
PublishedOct 6, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php.

Affected Platforms (CPE)

πŸ“¦
Formget

Easy Contact Form Solution

<= 1.6

References & Advisories

Related Vulnerabilities