ThreatPress

WordPress Vulnerability Database

Back

WordPress 123ContactForm plugin <= 1.5.6 - Validation Bypass via Plugin Verification vulnerability

Product
123ContactForm
Description
Validation Bypass via Plugin Verification vulnerability found by Sucuri in WordPress 123ContactForm plugin (versions <= 1.5.6).
Solution
2021-01-20 - we were unable to find a patched version of this plugin. Notification from WordPress plugin repository: "This plugin has been closed as of October 27, 2020 and is not available for download. Reason: Security Issue."
Classification
Type Bypass Vulnerability
OWASP Top 10 A2: Broken Authentication and Session Management
References
Vulnerability details
Plugin changelog
CVE
Name CVE-N/A
Versions
Affected In <= 1.5.6
Disclosure date
2021-01-19
Credits
Sucuri