Description
WordPress International Sms For Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Milad karimi
References
www.exploit-db.com/exploits/50719 (ExploitDB-50719)
wordpress.org/plugins/cf7-international-sms-integration/ (Product Reference)
www.vulncheck.com/...onal-sms-contact-form-7-integration-xss (VulnCheck Advisory: WordPress International Sms Contact Form 7 Integration 1.2 XSS)