Extension WordPress
Vulnérabilités VS Contact Form
Cette page rassemble les failles publiées pour VS Contact Form, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de VS Contact Form
4 fiches
VS Contact Form <= 14.7 – CAPTCHA Bypass
The VS Contact Form plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.7. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
*-14.7
14.8
29/03/2024
VS Contact Form <= 13.9 – Missing Authorization
The VS Contact Form plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 13.9. Exact implications of this vulnerability are unknown.
*-13.9
14.0
05/09/2023
VS Contact Form <= 11.5 – Reflected Cross-Site Scripting
The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for…
*-11.5
11.6
25/05/2022
Very Simple Contact Form <= 11.5 – Captcha Bypass
The plugin Very Simple Contact Form in versions up to and including 11.4 uses a captcha that can be bypassed by bots. Version 11.5 removes the captcha code leaving the contact form vulnerable.
*-11.5
11.6
22/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.