Contact Builder by Themify <= 1.4.5 - Email Injection
Strategic Overview
<= 1.4.5N/AVulnerability Overview
The Contact Builder by Themify plugin is vulnerable to email injection in versions up to, and including 1.4.5. This makes it possible for attackers to forward contact form submissions as a "copy" to the contact-email supplied even when the setting is disabled. In addition, the contact-message does not do any input sanitization allowing HTML to be injected into the message content. This was being actively exploited to craft phishing emails and sending those via the vulnerable sites.
Technical Analysis
REMEDIATION: Update to version 1.4.6, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C