CyberSec.Space Logo
返回 CVE 浏览器

CVE-2014-7240

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0170%
EPSS Percentile40.44th
Published2017年10月6日
Last Modified2026年5月13日

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php.

Affected Platforms (CPE)

📦
Formget

Easy Contact Form Solution

<= 1.6

References & Advisories

相关漏洞威胁