Plugin Vulnerability Hub
Plugin 1 known issue Latest disclosed Feb 25, 2022

Contact Form X Vulnerabilities

Review known vulnerability records for the WordPress plugin Contact Form X (`contact-form-x`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2022-25601, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
1
High or Critical
0
Patch Coverage
100%
Last Updated
Jan 22, 2024
Priority CVE Quick Links

Fast paths into Contact Form X CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
1
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Contact Form X so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
1 record include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2022-25601
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Known Vulnerabilities

Reports for Contact Form X

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2022-25601
CVE-2022-25601: Contact Form X <= 2.4 - Reflected Cross-Site Scripting

Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions

Published
Feb 25, 2022
Patched Release
2.4.1
Affected Versions
Versions up to 2.4
Next Step
Update to 2.4.1 or newer if supported.