The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 10 Jun 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
10web
10web spidercontacts |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:10web:spidercontacts:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
10web
10web spidercontacts |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T15:00:41.459Z
Reserved: 2024-06-22T21:22:03.075Z
Link: CVE-2024-6272
Updated: 2024-08-01T15:00:34.493Z
Status : Analyzed
Published: 2024-07-31T06:15:03.637
Modified: 2025-06-10T16:03:21.030
Link: CVE-2024-6272
No data.
OpenCVE Enrichment
No data.
Weaknesses