cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forquick-contact-form quick-contact-form

Direction: ascending
Jun 06, 2024

Quick Contact Form # 7e32520d86675f60cdeac530f6e120485d98fb69

Application

Quick Contact Form

Date
Feb 28, 2022
Research Description
Quick Contact Form [quick-contact-form] < 8.0.2 WordPress Quick Contact Form plugin < 8.0.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Quick Contact Form plugin (versions < 8.0.2).
Affected versions
Min -, max -.
Status
vulnerable

Quick Contact Form # CVE-2023-23885

CVE, Research URL

CVE-2023-23885

Application

Quick Contact Form

Date
Apr 07, 2023
Research Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
Affected versions
Min -, max -.
Status
vulnerable

Quick Contact Form # CVE-2022-47608

CVE, Research URL

CVE-2022-47608

Application

Quick Contact Form

Date
Apr 25, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Quick Contact Form # CVE-2023-25035

CVE, Research URL

CVE-2023-25035

Application

Quick Contact Form

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form : from n/a through 8.0.3.1.
Affected versions
Min -, max -.
Status
vulnerable
Nov 14, 2024

Quick Contact Form # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Application

Quick Contact Form

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable
May 27, 2025

Quick Contact Form # CVE-2025-48245

CVE, Research URL

CVE-2025-48245

Application

Quick Contact Form

Date
May 23, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fullworks Quick Contact Form allows Reflected XSS. This issue affects Quick Contact Form : from n/a through 8.2.1.
Affected versions
Min -, max -.
Status
vulnerable