CVE-2025-29000
7.5August Infotech · Multi-language Responsive Contact Form
A missing authorization vulnerability in the Multi-language Responsive Contact Form plugin allows unauthenticated users to access restricted functionality due to improper access control.
Executive summary
A critical missing authorization flaw in the August Infotech Multi-language Responsive Contact Form plugin allows unauthenticated attackers to bypass access controls and potentially access sensitive data.
Vulnerability
The vulnerability is a missing authorization flaw (CWE-862) within the plugin, which fails to perform necessary capability checks. This allows an unauthenticated attacker to interact with restricted functions that should be protected by access control lists.
Business impact
This vulnerability poses a significant risk to data confidentiality, as unauthorized parties may access information not intended for public view. With a CVSS score of 7.5, the flaw is classified as High severity. Successful exploitation could lead to unauthorized data exposure or administrative function abuse, potentially compromising the integrity of the WordPress installation and associated business operations.
Remediation
Immediate Action: Since no specific patch version is currently identified, administrators should immediately deactivate and remove the Multi-language Responsive Contact Form plugin from their environments until a secure update is released by August Infotech.
Proactive Monitoring: Security teams should audit web server access logs for suspicious requests directed at plugin-specific endpoints, particularly those originating from unauthorized or unexpected IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts to plugin-specific directories and administrative endpoints to provide a layer of virtual patching.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
The presence of a missing authorization flaw in a widely used plugin type requires immediate attention to prevent unauthorized access. Administrators must prioritize the removal of the vulnerable component to eliminate the attack surface, as relying on monitoring alone is insufficient for high-severity authorization bypass vulnerabilities.
Sources
Originally found and disclosed by ch4r0n | Patchstack Bug Bounty Program, per the CVE Program record.