Description
WordPress Plugin Easiest Contact Form for WordPress-AP Contact Form [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Easiest Contact Form for WordPress-AP Contact Form version 1.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
WordPress Plugin Contextual Related Posts Cross-Site Request Forgery (2.9.3)
PostgreSQL Improper Access Control Vulnerability (CVE-2016-7048)
WordPress Plugin WordPress Leads Cross-Site Scripting (1.6.2)
Grafana Authentication Bypass by Spoofing Vulnerability (CVE-2023-3128)
WordPress Plugin Login with phone number Security Bypass (1.7.26)