Broken Access Control in August Infotech Multi-language Responsive Contact Form
CVE-2025-29000
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 July 2025
What is CVE-2025-29000?
The August Infotech Multi-language Responsive Contact Form is vulnerable to a missing authorization flaw that enables unauthorized access to certain functionalities not adequately protected by Access Control Lists (ACLs). This vulnerability affects versions from n/a through 2.8, allowing attackers to exploit the system's inadequate restrictions and potentially access sensitive functionality. Users are urged to update and secure their applications promptly to safeguard against these unauthorized behaviors.
Affected Version(s)
Multi-language Responsive Contact Form <= 2.8
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ch4r0n (Patchstack Alliance)