The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed in the environment.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-14T05:33:00.221Z
Updated: 2024-08-01T20:33:52.480Z
Reserved: 2024-04-24T20:00:16.133Z
Link: CVE-2024-4144

Updated: 2024-08-01T20:33:52.480Z

Status : Awaiting Analysis
Published: 2024-05-14T16:17:33.483
Modified: 2024-11-21T09:42:16.350
Link: CVE-2024-4144

No data.