Skip to main content

Threat intelligence

Pay with Contact Form 7 <= 1.0.4 - Cross-Site Request Forgery

CVE-2025-24772 · pay-with-contact-form-7

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Pay With Contact Form 7 at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Pay with Contact Form 7 <= 1.0.4 - Cross-Site Request Forgery
Affected software
pay-with-contact-form-7(Plugin)
Affected versions
  • ≤ 1.0.4
Authentication
Not specified in feed title — see source advisory
Vulnerability type
CSRF
Published
5 June 2025
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
May trick authenticated users into performing unintended actions.
Source

Data imported from Wordfence Intelligence (advisory 0e05bad8-2093-4ca8-8c24-ae513ae4f1b9). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Pay With Contact Form 7 version against this catalog when the Defence plugin is connected to your WordPress site.