Contact Form 7 Datepicker Plugin (WordPress) Warning
2916Warning Date
Severity Level
Warning Number
Target Sector
5 April, 2020
● High
2020-1094
All
Description:
WordPress has released a warning to address a vulnerability in the following product:
- Contact Form 7 Datepicker to and before version 2.6.0
Threats:
Attacker could exploit the vulnerability by doing the following:
- Cross-site scripting (XSS) attack
Best practice and Recommendations:
The CERT team encourages users to deactivate and remove the Contact Form 7 Datepicker plugin if it is installed on your site.