CVE-2025-30935

WordPress Contact Form <= 2.0.12 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Contact Form allows DOM-Based XSS. This issue affects Contact Form: from n/a through 2.0.12.


We have discovered 29 live websites that are affected by CVE-2025-30935.

Run a Free Instant Scan




Affected Software

Product  Contact Form Ready
Category Wordpress Plugins
Vulnerable Domains29 live websites (100% of Contact Form Ready install base)
Vulnerable Versions
  • from 0 through 2.0.12
Vulnerable Versions Count3 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 6, 2025
  • Updated - Jun 6, 2025

Credits

  • theviper17 (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-30935
United States9 websites



Spain3 websites
Australia2 websites
Germany2 websites
GB2 websites
Netherlands2 websites
Russia2 websites
Brazil1 websites
Switzerland1 websites
Chile1 websites

Website Distribution by TLD

Number of websites using CVE-2025-30935
.com15 websites
.nl2 websites
.ru2 websites
.ch1 websites
.com.au1 websites
.de1 websites
.es1 websites
.fi1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-30935

Top websites that are affected by CVE-2025-30935. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.nl Netherlands*,***,***
********.es Spain*,***,***
*********.ru Russia**,***,***
***********.ru Russia**,***,***
********************.**.il Israel**,***,***
*********.nl Netherlands**,***,***
*************.fi Finland**,***,***
*************.lt Lithuania**,***,***
****************.com Germany**,***,***
**************.com United States**,***,***
See full domain list

FAQ

CVE-2025-30935 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Contact Form Ready
A total of 29 websites have been identified as vulnerable to CVE-2025-30935, based on global website indexing conducted by WebTechSurvey.
The Contact Form Ready is affected by the CVE-2025-30935 vulnerability.
Contact Form Ready versions up to and including 2.0.12 are vulnerable to CVE-2025-30935.