Cyber Resilience

CVE-2023-2802

Themefic Ultimate Addons For Contact Form 7 ≤ 3.1.29

Public PoC
Published
14 August 2023
Modified
21 November 2024
CVSS Score v3.1 4.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score 0.0047 39th percentile
Risk Priority 34 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2023-2802 is a medium-severity an unspecified weakness vulnerability in Themefic Ultimate Addons For Contact Form 7. Its CVSS base score is 4.8 (Medium).

Operationally, ranked at the 39th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability…

more

is disallowed (for example in multisite setup)

CWE(s)
None listed

Related Threats

CVEs Like This One

CVE-2025-6220Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2025-6756Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2023-49766Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2023-30495Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2023-30493Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2023-2803Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2023-1615Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2025-6212Same product: Themefic Ultimate Addons For Contact Form 7
CVE-2023-28989Same product class: WordPress / CMS plugin
CVE-2024-34445Same product class: WordPress / CMS plugin

Affected Assets

themefic
ultimate addons for contact form 7
≤ 3.1.29

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References