Cross-Site Request Forgery Vulnerability in Pay with Contact Form 7 by cmsMinds
CVE-2025-24772

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-24772?

A Cross-Site Request Forgery vulnerability exists in the Pay with Contact Form 7 product by cmsMinds. This vulnerability can allow malicious actors to execute unauthorized actions on behalf of users without their consent. The affected versions, including 1.0.4, expose users to potential security risks if not mitigated. Website administrators are advised to update to patched versions and implement security best practices to safeguard against CSRF attacks. For detailed information on the vulnerability, refer to the provided reference.

Affected Version(s)

Pay with Contact Form 7 <= 1.0.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

haudayroi - BlueRock (Patchstack Alliance)
.
CVE-2025-24772 : Cross-Site Request Forgery Vulnerability in Pay with Contact Form 7 by cmsMinds