Stored Cross-Site Scripting in Ultra Addons for Contact Form 7 Plugin by WordPress
CVE-2025-6756
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 July 2025
What is CVE-2025-6756?
The Ultra Addons for Contact Form 7 plugin for WordPress contains a vulnerability that allows attackers to exploit Stored Cross-Site Scripting (XSS) through the UACF7_CUSTOM_FIELDS shortcode. This issue arises from inadequate input sanitization and output encoding on attributes supplied by users. Authenticated attackers with contributor-level access can inject malicious web scripts, which will execute when any user accesses the affected page, potentially leading to severe security risks.
Affected Version(s)
Ultra Addons for Contact Form 7 * <= 3.5.21