CVE-2025-24727: WordPress Contact Form to Email Plugin <= 1.3.52 - Cross Site Scripting (XSS) vulnerability
Published Jan 24, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Contact Form Email contact-form-to-email allows Stored XSS.This issue affects Contact Form Email: from n/a through <= 1.3.52.
Affected Software
3 affected components
CodePeople Contact Form Email Wordpress<1.3.53
CodePeople Contact Form Email<=1.3.52
WordPress Contact Form to Email Plugin<=1.3.52
Remediation
Information
Update the WordPress Contact Form Email wordpress plugin to the latest available version (at least 1.3.53).
Event History
Jan 24, 2025
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24727?
CVE-2025-24727 has been categorized with a severity rating indicating a significant risk of Stored XSS vulnerabilities.
2
How do I fix CVE-2025-24727?
To remediate CVE-2025-24727, update the CodePeople Contact Form Email to version 1.3.53 or later.
3
What type of vulnerability is CVE-2025-24727?
CVE-2025-24727 is a Stored Cross-site Scripting (XSS) vulnerability affecting the Contact Form Email plugin.
4
Which versions are affected by CVE-2025-24727?
CVE-2025-24727 affects CodePeople Contact Form Email versions from n/a through 1.3.52.
5
Who is the vendor for the product affected by CVE-2025-24727?
The vendor for the affected product CVE-2025-24727 is CodePeople.