CVE-2019-25145 HIGH

CVE-2019-25145: Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injection

Vendor Smub
Product Contact Form & SMTP Plugin for WordPress by PirateForms
Weakness CWE-79 · XSS
Published June 7, 2023
Last update April 8, 2026

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary HTML in emails that could be used to phish unsuspecting victims.

Key dates

02Disclosure timeline

June 7, 2023 CVE published
April 8, 2026 Record updated