Reflected XSS Vulnerability in Contact Form 7 – Paystack Add-on by WordPress
CVE-2025-23655
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 February 2025
What is CVE-2025-23655?
A reflected cross-site scripting vulnerability exists in the Contact Form 7 – Paystack Add-on for WordPress, affecting versions from n/a to 1.2.3. This flaw occurs due to inadequate input sanitization during web page generation, allowing an attacker to inject malicious scripts into a web page. When users interact with the affected plugin, the embedded scripts could execute in their browsers, potentially leading to data theft or further exploits. It is crucial for users of this add-on to update to a secure version and implement best practices for web application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form 7 – Paystack Add-on <= 1.2.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved