Contact Builder by Themify <= 1.4.5 - Email Injection

2020-07-13 00:00
David Cucala

Strategic Overview

Status
Patched in 1.4.6
Affected Version<= 1.4.5
CVSS5.3Medium
CVEN/A
View all Contact Builder by Themify vulnerabilities

Vulnerability Overview

The Contact Builder by Themify plugin is vulnerable to email injection in versions up to, and including 1.4.5. This makes it possible for attackers to forward contact form submissions as a "copy" to the contact-email supplied even when the setting is disabled. In addition, the contact-message does not do any input sanitization allowing HTML to be injected into the message content. This was being actively exploited to craft phishing emails and sending those via the vulnerable sites.

Technical Analysis

REMEDIATION: Update to version 1.4.6, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C