Wordpress Multiple Third Party Plugins Multiple Vulnerabilities
Description
(#Several vulnerabilities have been identified in third party plugins for WordPress:#- Vertical image slider: multiple cross-site scripting and cross-site request forgery#- Contact Form: predictable Captcha with seed recovery attack#- Custom Sidebars: cross-site scripting in the parameter cs-msg of the widgets.php web page.##Proofs of concept exist.)
Vulnerable Products
Vulnerable Software: WordPress (WordPress) -
Solution
Version 7.4.1.1 of Contact Form and 2.1.0.2 of Custom Sidebars fixes the vulnerability impacting it.