漏洞描述
WordPress Contact Form 7 Captcha plugin before 0.1.2 contains a reflected cross-site scripting vulnerability. It does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/4fd2f1ef-39c6-4425-8b4d-1a332dabac8d↗wordpress.orghttps://wordpress.org/plugins/contact-form-7-simple-recaptcha↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-2187↗github.comhttps://github.com/ARPSyndicate/cvemon↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗