CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Themefic 1Ultimate Addons For Contact Form 7 Jul 16, 2025 Jul 1, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up to, and including, 3.5.21 due to insufficient input...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Jul 8, 2025 Jun 26, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and output escaping. The u...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Jul 9, 2025 Jun 18, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Apr 28, 2026 Dec 20, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Ultimate Addons for Contact Form 7.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3....Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Apr 28, 2026 Dec 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Stored XSS.This issue affects Ultimate Addons for Contact Form 7: f...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Nov 21, 2024 Sep 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions. |
1Themefic 1Ultimate Addons For Contact Form 7 Nov 21, 2024 Aug 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used agains...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Nov 21, 2024 Aug 14, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...Show more |
1Themefic 1Ultimate Addons For Contact Form 7 Nov 21, 2024 Jun 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions. |
1Themefic 1Ultimate Addons For Contact Form 7 Nov 21, 2024 Jun 9, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any author...Show more |