Stored XSS Vulnerability in Contact Form 7 Star Rating by ThemLogger
CVE-2025-27304
5.9MEDIUM
Key Information:
- Vendor
- Themelogger
- Status
- Contact Form 7 Star Rating With Font Awesome
- Vendor
- CVE Published:
- 24 February 2025
Summary
The vulnerability in themelogger's Contact Form 7 Star Rating with Font Awesome allows attackers to exploit improper input neutralization during web page generation. This leads to Stored Cross-site Scripting (XSS), placing users at risk by enabling malicious scripts to be stored and executed within user interactions on the affected application. It is crucial for website administrators using this plugin version 1.3 and earlier to secure their systems to prevent potential exploitation.
Affected Version(s)
Contact Form 7 Star Rating with font Awesome <= 1.3
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)