Cross-Site Request Forgery in DigitalDonkey Multilang Contact Form Plugin
CVE-2025-62896

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 October 2025

What is CVE-2025-62896?

A Cross-Site Request Forgery (CSRF) vulnerability in the DigitalDonkey Multilang Contact Form plugin allows attackers to execute unauthorized actions on behalf of authenticated users. This issue can lead to stored cross-site scripting (XSS) attacks, impacting the security and privacy of users. The vulnerability affects all versions of the Multilang Contact Form plugin up to 1.5, making it essential for website administrators to take prompt action to mitigate the risk.

Affected Version(s)

Multilang Contact Form <= n/a

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien | Patchstack Bug Bounty Program
.