Release date:
Updated on: 2013-02-23
Affected Systems:
WordPress Contact Form Plugin 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58089
WordPress Contact Form is a simple and flexible Contact Form plug-in.
Contact Form 3.34 and other versions of wp-content/plugins/contact-form-plugin/trunk/contact_form.php do not properly filter the index. the "cntctfrm_contact_message" GET parameter value in php can cause arbitrary HTML and script code execution in the context of the affected site.
<* Source: vendor
Link: http://secunia.com/advisories/52179/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/extend/plugins/contact-form-7/