CVE-2025-48245: WordPress Quick Contact Form plugin <= 8.2.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fullworks Quick Contact Form allows Reflected XSS. This issue affects Quick Contact Form : from n/a through 8.2.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Reflected XSS.This issue affects Quick Contact Form: from n/a through <= 8.2.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48245?
CVE-2025-48245 has a medium severity rating due to its ability to allow attackers to execute scripts in users' browsers.
How do I fix CVE-2025-48245?
To fix CVE-2025-48245, upgrade the Fullworks Quick Contact Form plugin to version 8.2.2 or later.
What is the main impact of CVE-2025-48245?
The main impact of CVE-2025-48245 is reflected cross-site scripting, which can lead to unauthorized actions performed on behalf of users.
Which versions of Quick Contact Form are affected by CVE-2025-48245?
CVE-2025-48245 affects all versions of Quick Contact Form up to and including 8.2.1.
Who is the vendor for CVE-2025-48245?
The vendor for CVE-2025-48245 is Fullworks, who developed the Quick Contact Form software.