CVE-2025-54684: WordPress Integration for Contact Form 7 and Constant Contact Plugin plugin <= 1.1.7 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Integration for Contact Form 7 and Constant Contact allows Stored XSS. This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through 1.1.7.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Integration for Contact Form 7 and Constant Contact cf7-constant-contact allows Stored XSS.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through <= 1.1.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54684?
CVE-2025-54684 has been classified as a high severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-54684?
To fix CVE-2025-54684, update the CRM Perks Integration for Contact Form 7 and Constant Contact to the latest version beyond 1.1.7.
What impact does CVE-2025-54684 have on my website?
CVE-2025-54684 could allow an attacker to inject malicious scripts into web pages viewed by other users, potentially compromising user data.
Which software versions are affected by CVE-2025-54684?
CVE-2025-54684 affects Integration for Contact Form 7 and Constant Contact versions up to and including 1.1.7.
Where can I find more information about CVE-2025-54684?
More detailed information about CVE-2025-54684 can be found in vulnerability databases and security advisories specific to the affected software.