Input validation vulnerability in Encrypted Contact Form 1.1

A security bug in a WordPress plugin called Encrypted Contact Form before version 1.1 allowed people to access an administrator’s account without needing the password. This allowed them to run scripts on the website which could do things like steal data or take control of the website.

Detected in:

Encrypted Contact Form open vulnerable versions: >= * < 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.