Input validation vulnerability in UTM tags + Landing page + “gclid” tracking for Contact Form 7 2.1

The way that UTM tags, landing pages, and “gclid” tracking are set up in the Contact Form 7 plugin for WordPress can be easily exploited by hackers. This is because the plugin doesn’t properly check for a security code, making it possible for someone to make changes to the settings or insert harmful code without needing to be authenticated. All versions of the plugin up to and including 2.1 are at risk. To fix this problem, the plugin needs to add proper security measures to prevent unauthorized access.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.