← WordPress Vulnerabilities
WordPress security by component

Contact Form by FormGet

Contact Form by FormGet is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 23, 2023; the highest CVE/CNA score is 6.4.

Plugin slug: formget-contact-form

CVE-2023-5125: Contact Form by FormGet: Cross-site scripting

Contact Form by FormGet is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedSep 23, 2023
Safe version guidanceSee mitigation notes
Safe version
Sep 23, 2023 CVE-2023-5125
Contact Form by FormGet: Cross-site scripting
Contact Form by FormGet is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4