Cross-site Scripting Vulnerability in FormLift for Infusionsoft Web Forms by Adrian Tobey
CVE-2025-47654
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2025
What is CVE-2025-47654?
A vulnerability exists in FormLift for Infusionsoft Web Forms developed by Adrian Tobey due to improper handling of input during web page generation. This flaw allows attackers to exploit reflected Cross-site Scripting (XSS) vulnerabilities, potentially compromising user data and session integrity. The issue affects versions of the plugin up to 7.5.20, highlighting the importance of immediate attention to upgrade and secure web forms.
Affected Version(s)
FormLift for Infusionsoft Web Forms <= 7.5.20