Security News > 2020 > April > Unpatched Flaw in Discontinued Plugin Exposes WordPress Sites to Attacks

Unpatched Flaw in Discontinued Plugin Exposes WordPress Sites to Attacks
2020-04-03 11:40

A stored cross-site scripting vulnerability in the Contact Form 7 Datepicker WordPress plugin will not receive a patch, leaving websites exposed to attacks, WordPress security firm Defiant reports.

The plugin, designed to integrate with the Contact Form 7 contact form management plugin, had over 100,000 installations when the vulnerability was discovered.

The WordPress plugin's team has already removed Contact Form 7 Datepicker from the repository for review.

Contact Form 7 Datepicker was designed to help users add a datepicker to forms generated by Contact Form 7, and also features the ability to modify settings for these datepickers.

Site admins are advised to deactivate and remove the Contact Form 7 Datepicker plugin and find an alternative plugin that can provide similar functionality.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/UOUE345UE5E/unpatched-flaw-discontinued-plugin-exposes-wordpress-sites-attacks

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159
Plugin 2 0 13 1 0 14