Reflected XSS Vulnerability in Contact Us By Lord Linus Plugin
CVE-2025-25127

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
3 March 2025

Summary

The vulnerability in the Contact Us By Lord Linus plugin arises from improper handling of input during web page generation, resulting in a reflected XSS flaw. This issue allows malicious actors to inject executable scripts into web pages, compromising user interactions and potentially stealing sensitive data. The affected versions, up to and including 2.6, require immediate attention to mitigate exposure and protect users.

Affected Version(s)

Contact Us By Lord Linus <= 2.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.