CVE · Medium

CVE-2023-0143 — Send PDF for Contact Form 7 [send-pdf-for-contact-form-7] < 0.9.9.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0143 Send PDF for Contact Form 7 [send-pdf-for-contact-form-7] < 0.9.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 0.9.9.2 0.9.9.2 2023-01-11

CVE-2023-0143

The Send PDF for Contact Form 7 plugin in versions prior to 0.9.9.2 contains a cross-site scripting vulnerability that permits attackers to insert malicious scripts into websites, which execute when visitors access the site. The flaw could enable injection of harmful code including redirects, advertisements, and arbitrary HTML content. Version 0.9.9.2 and later resolve this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.