Stored XSS Vulnerability in Contact Form 7 Star Rating by ThemLogger
CVE-2025-27304

5.9MEDIUM

Key Information:

Vendor
Themelogger
Status
Contact Form 7 Star Rating With Font Awesome
Vendor
CVE Published:
24 February 2025

Summary

The vulnerability in themelogger's Contact Form 7 Star Rating with Font Awesome allows attackers to exploit improper input neutralization during web page generation. This leads to Stored Cross-site Scripting (XSS), placing users at risk by enabling malicious scripts to be stored and executed within user interactions on the affected application. It is crucial for website administrators using this plugin version 1.3 and earlier to secure their systems to prevent potential exploitation.

Affected Version(s)

Contact Form 7 Star Rating with font Awesome <= 1.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.