Stored Cross-Site Scripting Vulnerability in Smart Forms Plugin for WordPress
CVE-2025-5055
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 May 2025
What is CVE-2025-5055?
The Smart Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output sanitization in its admin settings. This flaw affects versions up to and including 2.6.98, enabling authenticated attackers with administrator access to insert malicious web scripts into pages. These injected scripts execute automatically when the affected pages are accessed, posing a significant risk to multi-site installations or setups where the 'unfiltered_html' capability is disabled.
Affected Version(s)
Smart Forms – when you need more than just a contact form * <= 2.6.98