Input validation vulnerability in Database for Contact Form 7 3.0.6

The Contact Form 7 plugin for WordPress has a security issue called Stored Cross-Site Scripting. This means that the plugin does not properly clean up the information it receives and sends out, making it easy for hackers to insert harmful code into the form. This can affect anyone who has contributor-level access or higher, and can cause the inserted code to run whenever someone accesses the form.

Detected in:

Database for Contact Form 7 fixed vulnerable versions: >= * <= 3.0.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.