Medium 4.3
2025-12-09< 4.3.7
CVE-2025-63056
Minimum safe version
4.3.7
Update to 4.3.7 or later to address 17 fixable vulnerabilities
CVE-2025-63056
CVE-2024-2198
CVE-2024-2200
CVE-2014-125095
CVE-2013-10022
Contact Form <= 3.82 - Authorization Bypass
Contact Form 3.36 - contact_form.php cntctfrm_contact_email Parameter XSS
Contact Form 3.82 - Unauthorized Language Manipulation
Multiple BestWebSoft Plugins - Authenticated Cross-Site Scripting (XSS)
WordPress Contact Form Plugin <= 3.82 - Unauthorized Language Manipulation
WordPress Contact Form Plugin <= 3.36 - Cross Site Scripting
CVE-2017-2171
CVE-2016-10869
CVE-2015-9295
CVE-2013-7475
CVE-2017-18491
CVE-2013-7481