Input validation vulnerability in Contact Form by Supsystic 1.7.27

The Contact Form by Supsystic plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects versions of the plugin up to and including version 1.7.27. The problem is that the plugin does not have any security measures in place to validate certain requests. This means that a malicious user could create a forged request and trick an administrator into performing an action, such as clicking on a link, without their knowledge.

Detected in:

Contact Form by Supsystic open vulnerable versions: >= * <= 1.7.27

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.