CVE-2025-24726: WordPress Contact Form 7 Widget plugin <= 1.2.1 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 1.2.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24726?
CVE-2025-24726 has a moderate severity rating due to its ability to allow stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-24726?
To fix CVE-2025-24726, update HT Contact Form 7 to version 1.2.2 or later.
What software is affected by CVE-2025-24726?
CVE-2025-24726 affects HT Contact Form 7 versions up to and including 1.2.1.
What type of vulnerability is CVE-2025-24726?
CVE-2025-24726 is an improper neutralization of input during web page generation vulnerability, commonly known as stored cross-site scripting (XSS).
How can CVE-2025-24726 impact my website?
If exploited, CVE-2025-24726 can allow an attacker to execute arbitrary scripts in the context of a user's browser session, potentially leading to data theft or unauthorized actions.