CVE-2025-24564

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 14, 2025
CWE ID 79

Summary

CVE-2025-24564 is a Cross-site Scripting (XSS) vulnerability affecting the Contact Form With Shortcode plugin on aviplugins.com. An attacker can exploit this issue by injecting malicious scripts into the contact form, potentially gaining unauthorized access to user data or taking control of the affected website. This vulnerability exists in versions 4.2.5 and below, and allows for reflected XSS attacks. Website administrators using these versions of Contact Form With Shortcode are strongly advised to update their plugins as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share