HIGH🇵🇱 Wersja polska

CVE-2019-25145

CVSS 7.2v3.1pub. 2023-06-07upd. 2026-04-08

The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary HTML in emails that could be used to phish unsuspecting victims.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Wpforms Contact Form

    APP
    Wpforms
    ≤ 2.5.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassXSS
CWE
References

Related vulnerabilities

CVE-2024-11273MEDIUM6.1same product

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise an...

CVE-2023-30500MEDIUM5.8same product

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPF...

CVE-2020-10385MEDIUM5.4same product

A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin...

CVE-2022-3574CRITICAL9.8PL ✓same vendor

CSV Injection w WPForms Pro — brak walidacji danych eksportu

CVE-2024-11205HIGH8.5same vendor

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...