Cross-Site Scripting Vulnerability in Billplz Addon for Contact Form 7 by Alvind
CVE-2025-31007
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 August 2025
What is CVE-2025-31007?
The Billplz Addon for WordPress Contact Form 7 is susceptible to a Cross-Site Scripting (XSS) issue due to improper handling of user-supplied input. This can potentially allow attackers to execute arbitrary scripts in the context of a user's browser session, leading to unauthorized data access or account compromise. Affected versions include those up to 1.2.0, necessitating users to update to mitigate this security risk.
Affected Version(s)
Billplz Addon for Contact Form 7 <= 1.2.0