CVE-2025-27303

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 79

Summary

CVE-2025-27303 is a Cross-site Scripting (XSS) vulnerability affecting the Contact Form 7 Star Rating plugin, version n/a through 1.10. An attacker can exploit this issue, classified as an Improper Neutralization of Input During Web Page Generation, to inject malicious scripts into themelogger's web pages. The attacker may gain the ability to execute arbitrary code in users' browsers, potentially leading to data theft or unauthorized actions. This vulnerability poses a significant risk and requires immediate patching to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share