The popular WP-ContactForm plugin has been found vulnerable to HTML Injection.
This could allow an attacker to compromise your blog if you are authenticated to your blog while at the same time visiting a page with the embedded attack. Another popular attack is using phishing type e-mails.
BlogSec is not aware of any fixes as yet. We will update this post when more information is available to us.
Credit to Mustlive for discovering and publishing the vulnerability.
Check BlogSec’s double agent post
for HTML Injection mitigation ideas.