🔐 CVE Alert

CVE-2025-23658

UNKNOWN 0.0

WordPress Advanced Angular Contact Form plugin <= 1.1.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tauhidul Alam Advanced Angular Contact Form advanced-angular-contact-form allows Reflected XSS.This issue affects Advanced Angular Contact Form: from n/a through <= 1.1.0.

CWE CWE-79
Vendor tauhidul alam
Product advanced angular contact form
Published Feb 14, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for tauhidul alam advanced angular contact form

Be the first to know when new unknown vulnerabilities affecting tauhidul alam advanced angular contact form are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Tauhidul Alam / Advanced Angular Contact Form
0 ≤ 1.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/advanced-angular-contact-form/vulnerability/wordpress-advanced-angular-contact-form-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program