Zestard
Zestard Admin Side Data Storage FOR Contact Form 7: vulnerabilidades y CVE
Zestard Admin Side Data Storage FOR Contact Form 7 tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-1779 | Media (5.3) | 0.39% | — | 23 feb 2024 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to,… |
| CVE-2024-1778 | Media (5.3) | 0.37% | — | 23 feb 2024 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to,… |
| CVE-2024-1777 | Media (4.3) | 0.20% | — | 23 feb 2024 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the… |
| CVE-2024-1776 | Alta (7.2) | 0.56% | — | 23 feb 2024 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user… |
| CVE-2023-24420 | Media (6.1) | 0.38% | — | 15 jun 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions. |