First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contact Form 7 Material Design | <=1.0.0 | |
Contact Form 7 Material Design | <=1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30522 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site request forgery.
To fix CVE-2025-30522, update the Contact Form 7 Material Design plugin to the latest version available beyond 1.0.0.
CVE-2025-30522 affects all versions of the Contact Form 7 Material Design plugin up to and including version 1.0.0.
CVE-2025-30522 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to stored cross-site scripting (XSS).
The vendor related to CVE-2025-30522 is Damian Orzol, the creator of the Contact Form 7 Material Design plugin.