Low severity3.5NVD Advisory· Published Jun 16, 2022· Updated Jun 17, 2026
CVE-2017-20055
CVE-2017-20055
Description
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.2 is able to address this issue. It is recommended to upgrade the affected component.
Affected products
4cpe:2.3:a:bestwebsoft:contact_form:4.0.0:*:*:*:*:wordpress:*:*+ 2 more
- cpe:2.3:a:bestwebsoft:contact_form:4.0.0:*:*:*:*:wordpress:*:*
- (no CPE)range: <4.0.2
- (no CPE)range: 4.0.0
- Range: <4.0.2
Patches
Vulnerability mechanics
References
3- seclists.org/fulldisclosure/2017/Feb/100nvdExploitMailing ListThird Party Advisory
- sumofpwn.nl/advisory/2016/stored_cross_site_scripting_vulnerability_in_contact_form_wordpress_plugin.htmlnvdExploitThird Party Advisory
- vuldb.comnvdThird Party Advisory
News mentions
0No linked articles in our index yet.