Vulnerability record · CVE-2021-25080 · published 24 January 2022
CVE-2021-25080: Contact Form Entries plugin stores unescaped IP headers, enabling stored XSS
Crmperks · Contact Form Entries
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise or escape the IP address it reads from headers such as CLIENT-IP and X-FORWARDED-FOR. That value is stored with the form entry and rendered without escaping, so an unauthenticated attacker can inject script that runs in a logged-in administrator's browser when the entry is viewed.
Description
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable without authentication, has public exploit detail and a very high EPSS score, and can lead to full WordPress admin compromise, though it requires an admin to view the poisoned entry.
What it is
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise or escape the IP address it reads from headers such as CLIENT-IP and X-FORWARDED-FOR. That value is stored with the form entry and rendered without escaping, so an unauthenticated attacker can inject script that runs in a logged-in administrator's browser when the entry is viewed.
Impact
An attacker can execute arbitrary JavaScript in an administrator's session, which in WordPress typically allows session theft, creation of admin accounts, or plugin and theme modification. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the plugin's public form submission path; no authentication is required to submit an entry, but the payload only fires when an authenticated admin views the entry, so user interaction by the victim is needed.
Exploitation
No CISA KEV listing, but EPSS is 0.842 (99.7th percentile) and the WPScan reference is tagged Exploit, indicating public exploit detail exists and exploitation is likely.
What to do
- Update Contact Form Entries to version 1.1.7 or later, which contains the fix in changeset 2450335.
- If immediate patching is not possible, disable the plugin or restrict access to the entries admin screen.
- Do not trust client-supplied IP headers; configure the web server or proxy to set a single authoritative client IP and strip CLIENT-IP and X-FORWARDED-FOR from untrusted sources.
- Apply output escaping and input validation to any header-derived data stored and later displayed in admin views.
- Review administrator accounts and sessions for signs of compromise after any suspected exploitation.
Detection
- Search stored form entries for script tags, event handlers or encoded JavaScript in IP address fields.
- Monitor web logs for requests containing crafted CLIENT-IP or X-FORWARDED-FOR headers with script payloads.
- Alert on unexpected administrator account creation, plugin installation or option changes following admin views of form entries.
- Check for outbound requests from admin browsers to unfamiliar domains after entries are opened.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://plugins.trac.wordpress.org/changeset/2450335 | PatchThird Party Advisory |
| https://wpscan.com/vulnerability/acd3d98a-aab8-49be-b77e-e8c6ede171ac | ExploitThird Party Advisory |
| https://plugins.trac.wordpress.org/changeset/2450335 | PatchThird Party Advisory |
| https://wpscan.com/vulnerability/acd3d98a-aab8-49be-b77e-e8c6ede171ac | ExploitThird Party Advisory |
Track CVE-2021-25080 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25080), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.