Reflected XSS Vulnerability in Thorsten Krug Multilang Contact Form Plugin
CVE-2025-22795
7.1HIGH
What is CVE-2025-22795?
A Cross-site Scripting (XSS) vulnerability exists in the Multilang Contact Form plugin developed by Thorsten Krug, allowing attackers to inject malicious scripts that can be executed in the context of a user's browser. This issue can lead to the exposure of sensitive information or compromise user sessions. The vulnerability affects versions from n/a up to 1.5, highlighting the importance of updating the plugin to mitigate potential security risks.
Affected Version(s)
Multilang Contact Form <= 1.5