CVE-2022-25601: WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25601?
CVE-2022-25601 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Contact Form X WordPress plugin (versions <= 2.4).
What is the severity of CVE-2022-25601?
The severity of CVE-2022-25601 is medium with a severity value of 6.1.
Which software versions are affected by CVE-2022-25601?
Versions <= 2.4.1 of the Contact Form X WordPress plugin, Fedora 34, Fedora 35, and Fedora 36 are affected by CVE-2022-25601.
How can I fix CVE-2022-25601?
To fix CVE-2022-25601, update the Contact Form X WordPress plugin to a version higher than 2.4.1 or apply the necessary patches provided by the plugin developer.
What is the CWE ID of CVE-2022-25601?
The CWE ID of CVE-2022-25601 is 79, which refers to Improper Neutralization of Input During Web Page Generation (Cross-site Scripting).