CVE-2025-52794: WordPress Creative Contact Form plugin <= 1.0.0 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Creative-Solutions Creative Contact Form allows Stored XSS. This issue affects Creative Contact Form: from n/a through 1.0.0.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Creative-Solutions Creative Contact Form sexy-contact-form allows Stored XSS.This issue affects Creative Contact Form: from n/a through <= 1.0.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52794?
CVE-2025-52794 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that allows for Stored XSS attacks, which can lead to a high severity rating.
How do I fix CVE-2025-52794?
To fix CVE-2025-52794, ensure that you update the Creative Contact Form plugin to the latest version starting from version 1.0.1 or later.
What versions of Creative Contact Form are affected by CVE-2025-52794?
CVE-2025-52794 affects the Creative Contact Form plugin versions up to and including 1.0.0.
What impact does CVE-2025-52794 have on my website?
CVE-2025-52794 can potentially allow attackers to execute malicious scripts through stored XSS, compromising user data and website integrity.
Is CVE-2025-52794 specific to WordPress?
Yes, CVE-2025-52794 specifically affects the WordPress version of the Creative Contact Form plugin.