Description
WordPress Plugin Easiest Contact Form for WordPress-AP Contact Form [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Easiest Contact Form for WordPress-AP Contact Form version 1.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
Drupal Core 9.0.x Cross-Site Scripting (9.0.0 - 9.0.13)
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-15882)
MySQL CVE-2018-2819 Vulnerability (CVE-2018-2819)
MySQL CVE-2024-21237 Vulnerability (CVE-2024-21237)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5487)