Medium 4.3
2025-06-30< 1.1.29
Easy Contact Form Lite <= 1.1.28 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
4.0.2
Update to 4.0.2 or later to address 5 fixable vulnerabilities
Easy Contact Form Lite <= 1.1.28 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-26962
CVE-2024-32147
CVE-2017-20055
WordPress Easy Contact Form Lite Plugin <= 1.0.7 - SQL Injection