Cross-Site Request Forgery Vulnerability in Contact Form With Captcha WordPress Plugin

Cross-Site Request Forgery Vulnerability in Contact Form With Captcha WordPress Plugin

CVE-2021-42358 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.

Learn more about our Wordpress Pen Testing.