Description
WordPress Plugin Contact Form by BestWebSoft is prone to an email header injection vulnerability because it fails to sufficiently sanitize input. Exploiting this issue may allow a remote attacker to insert arbitrary email headers into an HTTP response, which may aid in launching further attacks. WordPress Plugin Contact Form by BestWebSoft version 3.83 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that newlines are stripped from the 'name' field
References
Related Vulnerabilities
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.23)
WordPress Plugin WP Insightly for Contact Form 7 and Ninja Forms Cross-Site Scripting (1.0.7)
WordPress 2.8 Multiple Existing/Non-Existing Username Enumeration Weaknesses (0.6.2 - 2.8)
WordPress Plugin Bold Timeline Lite Cross-Site Scripting (1.1.4)