Masdiblogs maintains a WordPress plugin, wp_ajax_contact_form, that handles web forms and user input processing, where the observed vulnerability pattern centers on cross-site request forgery and cross-site scripting issues inherent to client-side form handling. Treat this as a narrow vendor profile around a single plugin component; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Masdiblogs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5809MEDIUM The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Jul 30, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-5808MEDIUM The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in | Jul 30, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Masdiblogs.
Media articles that mention a CVE ID that affects a product developed by Masdiblogs — matched by CVE ID, not by vendor name.