The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to retrieve form settings which includes Facebook app secrets.
Metrics
Affected Vendors & Products
References
History
Sat, 17 Jan 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to retrieve form settings which includes Facebook app secrets. | |
| Title | User Registration Using Contact Form 7 <= 2.5 - Authenticated (Subscriber+) Information Exposure | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-17T04:34:02.212Z
Reserved: 2025-11-06T19:06:39.317Z
Link: CVE-2025-12825
No data.
Status : Received
Published: 2026-01-17T05:16:09.070
Modified: 2026-01-17T05:16:09.070
Link: CVE-2025-12825
No data.
OpenCVE Enrichment
No data.