Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Contact Form allows DOM-Based XSS. This issue affects Contact Form: from n/a through 2.0.12.
We have discovered 29 live websites that are affected by CVE-2025-30935.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 29 live websites (100% of Contact Form Ready install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 3 versions ( 100% of all versions) |
![]() | 9 websites |
![]() | 3 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 1 websites |
![]() | 1 websites |
![]() | 1 websites |
.com | 15 websites |
.nl | 2 websites |
.ru | 2 websites |
.ch | 1 websites |
.com.au | 1 websites |
.de | 1 websites |
.es | 1 websites |
.fi | 1 websites |
.org | 1 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.nl | ![]() | *,***,*** | |
********.es | ![]() | *,***,*** | |
*********.ru | ![]() | **,***,*** | |
***********.ru | ![]() | **,***,*** | |
********************.**.il | ![]() | **,***,*** | |
*********.nl | ![]() | **,***,*** | |
*************.fi | ![]() | **,***,*** | |
*************.lt | ![]() | **,***,*** | |
****************.com | ![]() | **,***,*** | |
**************.com | ![]() | **,***,*** |
FAQ