Junglewise Threat Intelligence

CVE-2021-47870: GetSimple CMS My SMTP Contact Plugin stored XSS

CVE-2021-47870 · Severity: medium · CVSS 5.4 · Published 2026-01-21

Executive brief

A security vulnerability exists in the My SMTP Contact plugin for GetSimple CMS, a tool used to manage contact forms and email settings. An attacker can inject malicious scripts into the website's management interface. If an administrator views the affected page, the attacker could potentially take control of their session, modify website content, or gain unauthorized access to sensitive administrative functions.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in GetSimple CMS My SMTP Contact Plugin version 1.1.2. While the plugin utilizes the PHP function htmlspecialchars() for sanitization, this defense is bypassed by supplying dangerous characters as escaped hex bytes (e.g., \x3c for '<'). An attacker with low-level privileges can inject malicious JavaScript that executes in the context of an administrator's session when they visit the plugin's settings page. Public exploits demonstrate that this can be chained with CSRF and existing core vulnerabilities to achieve Remote Code Execution (RCE) by hijacking administrative XHR requests to modify theme files.

Affected products

  • GetSimple CMS My SMTP Contact Plugin 1.1.2

Timeline

  • 2021-04-22: disclosed: Original exploit research by Bobby Cooke (boku) published.
  • 2026-01-21: advisory: CVE-2021-47870 published.

References