First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Contact Form Email allows Stored XSS. This issue affects Contact Form Email: from n/a through 1.3.52.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Contact Form Email | <=1.3.52 | |
WordPress Contact Form to Email Plugin | <=1.3.52 |
Update the WordPress Contact Form Email wordpress plugin to the latest available version (at least 1.3.53).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24727 has been categorized with a severity rating indicating a significant risk of Stored XSS vulnerabilities.
To remediate CVE-2025-24727, update the CodePeople Contact Form Email to version 1.3.53 or later.
CVE-2025-24727 is a Stored Cross-site Scripting (XSS) vulnerability affecting the Contact Form Email plugin.
CVE-2025-24727 affects CodePeople Contact Form Email versions from n/a through 1.3.52.
The vendor for the affected product CVE-2025-24727 is CodePeople.