Input validation vulnerability in Custom Contact Forms 5.1.0.3

The Custom Contact Forms plugin for WordPress is not secure in versions 5.1.0.2 and below. Attackers can inject malicious scripts into pages if they can get someone to take an action, like clicking on a link. This is possible because the plugin does not properly sanitize and escape user inputs.

Detected in:

Custom Contact Forms fixed vulnerable versions: >= * < 5.1.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.