Contact Form vCard Generator <= 2.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'wp-gvc-cf-download-id' Parameter
medium
The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf_check_download_request' function in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to export sensitive Contact Form 7 submis...
- CVSS:
- 5.3
- Affected:
- up to 2.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-13717 on NVD →
Contact Form vCard Generator <= 2.4 - Reflected Cross-Site Scripting
medium
The Contact Form vCard Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- CVSS:
- 6.1
- Affected:
- up to 2.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-39521 on NVD →
Contact Form vCard Generator <= 2.4 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form vCard Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve...
- CVSS:
- 7.2
- Affected:
- up to 2.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 2, 2025
CVE-2025-31582 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database