CVE-2025-63056: WordPress Contact Form by BestWebSoft plugin <= 4.3.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in bestwebsoft Contact Form by BestWebSoft contact-form-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by BestWebSoft: from n/a through <= 4.3.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63056?
The severity of CVE-2025-63056 is categorized as medium due to the missing authorization vulnerability allowing unauthorized access.
How do I fix CVE-2025-63056?
To fix CVE-2025-63056, update the BestWebSoft Contact Form plugin to version 4.3.6 or later where the vulnerability is addressed.
What versions are affected by CVE-2025-63056?
CVE-2025-63056 affects all versions of the BestWebSoft Contact Form plugin up to and including version 4.3.5.
What kind of vulnerability is CVE-2025-63056?
CVE-2025-63056 is a missing authorization vulnerability that allows exploitation of incorrectly configured access control security levels.
Who is impacted by CVE-2025-63056?
Users of the BestWebSoft Contact Form plugin who have versions 4.3.5 or earlier installed are at risk from CVE-2025-63056.