.. / CVE-2021-25063

Exploit for WordPress Contact Form 7 Skins <=2.5.0 - Cross-Site Scripting (CVE-2021-25063)

Description:

WordPress Contact Form 7 Skins plugin 2.5.0 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the tab parameter before outputting it back in an admin page.

Nuclei Template

View the template here CVE-2021-25063.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-25063.yaml
Copy

References:

https://wpscan.com/vulnerability/e2185887-3e53-4089-aa3f-981c944ee0bb
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-25063
https://github.com/ARPSyndicate/kenzer-templates