Description
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.
Weaknesses
- — CWE-79 Cross-Site Scripting (XSS)
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Simple Basic Contact Form | 0 to <=20250114 |
References
- https://wpscan.com/vulnerability/535ec1a1-b822-43c9-8264-6442199493d3/ (exploit vdb-entry technical-description)
Generated from the official CVE List on 23 Jun 2026 10:05 UTC.