CVE-2025-12825: Zealopensource User Registration Using Contact Form 7
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_cf7_form_data' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to retrieve form settings which includes Facebook app secrets.
Affected products
- Zealopensource User Registration Using Contact Form 7: up to and including 2.5
Published 2026-01-17. Last modified 2026-06-17.