Admin Side Data Storage For Contact Form 7
admin_side_data_storage_for_contact_form_7
Vendor: Zestard • 5 CVEs
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zestard 1Admin Side Data Storage For Contact Form 7 Jun 17, 2026 Feb 23, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to, and...Show more |
1Zestard 1Admin Side Data Storage For Contact Form 7 Jun 17, 2026 Feb 23, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, a...Show more |
1Zestard 1Admin Side Data Storage For Contact Form 7 Jun 17, 2026 Feb 23, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the set...Show more |
1Zestard 1Admin Side Data Storage For Contact Form 7 Jun 17, 2026 Feb 23, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied...Show more |
1Zestard 1Admin Side Data Storage For Contact Form 7 Jun 17, 2026 Jun 15, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions. |