Cross-Site Scripting Vulnerability in Billplz Addon for Contact Form 7 by Alvind
CVE-2025-31007

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2025

What is CVE-2025-31007?

The Billplz Addon for WordPress Contact Form 7 is susceptible to a Cross-Site Scripting (XSS) issue due to improper handling of user-supplied input. This can potentially allow attackers to execute arbitrary scripts in the context of a user's browser session, leading to unauthorized data access or account compromise. Affected versions include those up to 1.2.0, necessitating users to update to mitigate this security risk.

Affected Version(s)

Billplz Addon for Contact Form 7 <= 1.2.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.