Missing Authorization Vulnerability in Contact Form by Mega Forms
CVE-2025-58639
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 September 2025
What is CVE-2025-58639?
A missing authorization vulnerability exists in the Contact Form By Mega Forms plugin, allowing unauthorized users to exploit incorrectly configured access control security levels. This flaw impacts versions from n/a through 1.6.1, highlighting the importance of proper access controls to prevent exploitation and protect user data.
Affected Version(s)
Contact Form By Mega Forms <= 1.6.1