Stored Cross-Site Scripting Vulnerability in Smart Forms Plugin for WordPress
CVE-2025-5055

4.4MEDIUM

What is CVE-2025-5055?

The Smart Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output sanitization in its admin settings. This flaw affects versions up to and including 2.6.98, enabling authenticated attackers with administrator access to insert malicious web scripts into pages. These injected scripts execute automatically when the affected pages are accessed, posing a significant risk to multi-site installations or setups where the 'unfiltered_html' capability is disabled.

Affected Version(s)

Smart Forms – when you need more than just a contact form * <= 2.6.98

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joel Indra
.