CVE-2025-60169
7.1W3S Cloud Technology · W3SCloud Contact Form 7 to Zoho CRM
A Cross-Site Request Forgery (CSRF) vulnerability in the W3SCloud Contact Form 7 to Zoho CRM plugin allows for Stored Cross-Site Scripting (XSS) attacks.
Executive summary
A CSRF vulnerability in the W3SCloud Contact Form 7 to Zoho CRM plugin enables unauthenticated attackers to execute Stored XSS, potentially leading to unauthorized actions or data theft.
Vulnerability
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability that permits an unauthenticated attacker to inject malicious scripts into the application. This Stored XSS condition occurs because the plugin fails to properly validate requests, allowing attackers to force administrators or users to execute unintended actions.
Business impact
Successful exploitation of this vulnerability can lead to the compromise of user sessions, unauthorized data modification, or the execution of malicious scripts within the context of the victim's browser. Given the CVSS score of 7.1, this is a High severity issue that could facilitate account takeover or the theft of sensitive information processed by the CRM integration.
Remediation
Immediate Action: Review the vendor advisory for available security updates and apply them immediately to ensure the plugin is patched beyond version 3.2.
Proactive Monitoring: Monitor web server and application logs for unusual administrative activity or requests originating from unexpected sources that coincide with form submissions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious XSS payloads and suspicious cross-site requests targeting the plugin endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to the integrity of the integrated CRM data. Organizations using this plugin should prioritize updating to the latest version as soon as a patch is released, while simultaneously maintaining strict access controls and monitoring for anomalous web traffic.
Sources
Originally found and disclosed by Nguyen Xuan Chien | Patchstack Bug Bounty Program, per the CVE Program record.