First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vikas Ratudi VForm | <=3.1.9 | |
WordPress VForm plugin | <=3.1.9 |
Update the WordPress VForm plugin to the latest available version (at least 3.1.10).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30778 is categorized as a medium severity vulnerability due to its potential for causing reflected cross-site scripting (XSS) attacks.
To remediate CVE-2025-30778, upgrade Vikas Ratudi VForm to version 3.1.10 or later, which includes the necessary patches.
CVE-2025-30778 affects all versions of Vikas Ratudi VForm from n/a through 3.1.9.
Yes, the WordPress VForm plugin is vulnerable to CVE-2025-30778 if it is version 3.1.9 or earlier.
Due to CVE-2025-30778, attackers may exploit reflected XSS to execute malicious scripts in the context of users' browsers.