CVE-2025-13717: Ashishajani Contact Form Vcard Generator

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf_check_download_request' function in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to export sensitive Contact Form 7 submission data via the 'wp-gvc-cf-download-id' parameter, including names, phone numbers, email addresses, and messages.

Affected products

  • Ashishajani Contact Form Vcard Generator: up to and including 2.4

Published 2026-01-09. Last modified 2026-06-17.