Cross-Site Request Forgery in Creative Contact Form by Creative-Solutions
CVE-2025-52794

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 June 2025

What is CVE-2025-52794?

A Cross-Site Request Forgery (CSRF) vulnerability in the Creative Contact Form plugin allows attackers to exploit the vulnerability, leading to potential Stored Cross-Site Scripting (XSS) attacks. This flaw can be leveraged by malicious actors to trick users into submitting unauthorized requests, ultimately compromising the security of the application. The issue affects versions up to and including 1.0.0, highlighting the need for immediate updates and patches to ensure web security.

Affected Version(s)

Creative Contact Form <= 1.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.