Login

Plugin Vulnerabilities

A service to protect your site against vulnerabilities in WordPress plugins.

  • Why Plugin Vulnerabilities?
    • We Provide Fixes for Vulnerabilities
    • We Provide Accurate Vulnerability Information
    • Insightful Blocked Exploit Attempt Reporting
    • How We Are Improving the Security of WordPress Plugins
    • Proactive Monitoring for Vulnerabilities in New Versions of WordPress Plugins
    • Select Plugins to Receive Security Reviews
  • Sign Up
    • Set Up
  • PV Firewall
    • Set Up
    • Block Insights
    • WordPress Firewall Comparison
  • Other Services
    • WordPress Security Checkup
    • Plugin Security Review
    • Continuous Plugin Security Review Service
    • Theme Security Review
    • Hacked WordPress Website Cleanup
    • Abandoned WordPress Plugin Maintenance Service
    • Blue Hat Hacking Service for WordPress Plugins/Websites
    • Plugin Vulnerabilities Subscription for ClassicPress
    • Solutions for Web Hosts
    • Solutions for Security Providers
  • Plugin Search
    • WordPress Firewall Tester
    • WordPress Plugins Checker
    • Plugin Security Scorecard
    • Security Scorecard WordPress Plugin
    • WordPress REST API Route Checker
  • Research
    • Plugin Vulnerabilities Survey
    • Report Hacking of WordPress Website
    • Unfixed Security Issues in WordPress
    • Security Advisories on WordPress Plugin Developers
    • WP Security Researcher Database
    • Send us a Tip
  • About
    • WordPress Plugin Zero-Day Vulnerability Exploitation Info Sharing Partnership
    • Get Free Help Fixing A Security Vulnerability In Your WordPress Plugin
    • Contact Us
    • Feedback
    • Report a WordPress Plugin Vulnerability We Are Missing

Tag Archives: Contact Form Email

19 Nov 2021

Not Really a WordPress Plugin Vulnerability, Week of November 19

In reviewing reports of vulnerabilities in WordPress plugins to provide our customers with the best data on vulnerabilities in plugins they use, we often find that there are reports for things that don’t appear to be vulnerabilities. For more problematic reports, we release posts detailing why the vulnerability reports are false, but there have been a lot of that we haven’t felt rose to that level. In particular, are items that are not outright false, just the issue is probably more accurately described as a bug. For those that don’t rise to the level of getting their own post, we now place them in a weekly post when we come across them.

Stored Cross Site Scripting (XSS)  in Contact Form Email

With a claimed stored cross site scripting (XSS) vulnerability in Contact Form Email, the only information provide are these instructions: [Read more]

Plugin Vulnerabilities Posted in Not Really a WordPress Plugin Vulnerability Contact Form Email, Not Really a WordPress Plugin Vulnerability Leave a comment
2 Nov 2018

Full Disclosure of Vulnerability That Exposes Contact Form Submissions in WordPress Plugin with 30,000 Installs

Just yesterday we were discussing the problematic behavior of WordPress Support Forum moderators deleting discussions related to a vulnerabilities in plugins. What is of most concern with that is that they often do that while not making sure anything is done about getting the vulnerability fixed, which leaves websites vulnerable in instances where they shouldn’t be. Another reason that is problematic is that information on vulnerabilities can be helpful in finding other security issues in the same plugin or other  plugins.

Along those lines while writing up a post with the details of several vulnerabilities that had been fixed the other day in the plugin Contact Form Email we noticed a fairly serious issue still in the plugin. It turns out that anyone can download all of the contact form submissions made through the plugin. According to wordpress.org this plugin has 30,000+ active installations. [Read more]

Plugin Vulnerabilities Posted in Vulnerability Report Contact Form Email, Information Disclosure, Vulnerability Report Leave a comment
2 Nov 2018

Vulnerability Details: Reflected XSS, CSRF/XSS, and Persistent XSS Vulnerabilities in Contact Form Email

From time to time a plugin is closed on the Plugin Directory for an unexplained security issue without the discoverer putting out a report on the vulnerability and we will put out a post detailing the possible vulnerability that led to that so that we can provide our customers with more complete information on the security of plugins they use.

…


[Read more]

Plugin Vulnerabilities Posted in Vulnerability Insights Contact Form Email, Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS), Persistent Cross-Site Scripting (XSS), Reflected Cross-Site Scripting (XSS), Vulnerability Details Leave a comment

Post navigation

Follow Us

  • Google News
  • Bluesky
  • RSS

Latest Plugin Security Reviews

  • WordPress Plugin Security Review: FV Gravatar Cache
  • WordPress Plugin Security Review: Popup Builder
  • WordPress Plugin Security Review: WP Time Capsule
Powered by WordPress and WooCommerce
© 2016-2025 White Fir Design LLC | Privacy Policy
Fruitful theme by fruitfulcode
↑