
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12825 is a missing authorization vulnerability in the "User Registration Using Contact Form 7" WordPress plugin that allows unauthenticated attackers to retrieve sensitive form settings, including Facebook app secrets. It affects all versions of the plugin up to and including version 2.5. The vulnerability was disclosed on January 17, 2026, with the CVE record submitted by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the get_cf7_form_data function within the plugin, which fails to verify whether the requesting user has appropriate permissions before returning form configuration data. Because no authentication or authorization is enforced, any unauthenticated remote attacker can send a network request to invoke this function and receive the full form settings in response. The exposed data includes Facebook app secrets configured within the plugin's Contact Form 7 integration, which could be leveraged for further attacks against connected Facebook applications (Wordfence, WordPress Trac).
Successful exploitation results in unauthorized disclosure of sensitive configuration data, specifically Facebook app secrets stored within the plugin's form settings. An attacker who obtains a Facebook app secret could abuse it to impersonate the application, access Facebook API endpoints on behalf of the site, or potentially compromise user accounts linked through Facebook authentication. The integrity and availability of the WordPress site itself are not directly affected, but the credential exposure creates significant risk for third-party integrations and downstream account takeover scenarios (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12825 as of the available data. The EPSS score is approximately 0.047%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the lack of any authentication requirement makes it trivially exploitable by any attacker who can reach the target WordPress site over the network (Wordfence).
get_cf7_form_data function — typically accessible via wp-admin/admin-ajax.php with an appropriate action parameter.get_cf7_form_data.wp-admin/admin-ajax.php with action parameters related to get_cf7_form_data; repeated requests from a single IP or scanning patterns targeting this endpoint.admin-ajax.php without a valid session cookie or nonce, particularly from unfamiliar IP addresses; HTTP 200 responses to these unauthenticated requests indicating successful data retrieval.Users should update the "User Registration Using Contact Form 7" plugin to a version beyond 2.5, which includes the fix adding proper capability checks to the get_cf7_form_data function. The patch is available in the WordPress plugin repository as changeset 3433276. As an immediate workaround for sites that cannot update immediately, administrators should consider deactivating the plugin until patching is possible, and should rotate any Facebook app secrets that may have been exposed (WordPress Trac, Wordfence).
Wordfence, which discovered and reported the vulnerability, published a threat intelligence entry covering the technical details and remediation guidance. The vulnerability received standard coverage from automated vulnerability tracking services including VulDB, Vulners, and CIRCL. No notable researcher commentary or significant media coverage beyond routine vulnerability disclosure has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."