CVE-2025-12718
Quick Contact Form
Minimum safe version
8.2.7
Update to 8.2.7 or later to address 16 fixable vulnerabilities
CVE-2025-67471
WordPress Quick Contact Form Plugin <= 8.2.1 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Quick Contact Form 6.0 - Stored XSS
Quick Contact Form 6.2 - Unspecified XSS
WordPress Quick Contact Form Plugin < 8.0.6.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-47608
CVE-2023-23885
CVE-2023-25035
Quick Contact Form < 6.1 - Cross-Site Scripting
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Quick Contact Form Plugin 6.0 - Persistent XSS
WordPress Quick Contact Form Plugin <= 6.2 - Cross Site Scripting
WordPress Quick Contact Form plugin < 8.0.2 - Sensitive Information Disclosure vulnerability
WordPress Quick Contact Form plugin < 8.0.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability