Rapid7

vulnerability

WordPress Plugin: contact-form-manager: CVE-2017-20053: Cross-Site Request Forgery (CSRF)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Mar 1, 2017
Added
May 15, 2025
Modified
Apr 30, 2026

Description

A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Solution

contact-form-manager-plugin-cve-2017-20053
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.