CVE-2025-32679: WordPress User Registration Using Contact Form 7 plugin <= 2.4 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 user-registration-using-contact-form-7 allows Cross Site Request Forgery.This issue affects User Registration Using Contact Form 7: from n/a through <= 2.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32679?
CVE-2025-32679 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-32679?
To fix CVE-2025-32679, update the ZealousWeb User Registration Using Contact Form 7 plugin to version 2.3 or later.
Which versions are affected by CVE-2025-32679?
CVE-2025-32679 affects versions of User Registration Using Contact Form 7 up to and including 2.2.
What type of vulnerability is CVE-2025-32679?
CVE-2025-32679 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is the vendor affected by CVE-2025-32679?
The vendor affected by CVE-2025-32679 is ZealousWeb, specifically for their User Registration Using Contact Form 7 plugin.