cve/2008/CVE-2008-0198.md
2025-09-29 21:09:30 +02:00

796 B

CVE-2008-0198

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.

POC

Reference

No PoCs from references.

Github