Record summary

CVE-2021-25080 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Contact Form Entries – Contact Form 7, WPforms and more

CVE List1.1.7 to < 1.1.7affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-25080Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 1.7 KiB

GitHub

PoC details
GitHubCVE-2021-25080Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 1.7 KiB

GitHub

PoC details

References

3