CVE-2025-31045

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget elfsight-contact-form allows Retrieve Embedded Sensitive Data.This issue affects elfsight Contact Form widget: from n/a through <= 2.3.1.
Configurations

No configuration.

History

23 Apr 2026, 15:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

01 Apr 2026, 17:20

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/elfsight-contact-form/vulnerability/wordpress-elfsight-contact-form-widget-2-3-1-sensitive-data-exposure-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/elfsight-contact-form/vulnerability/wordpress-elfsight-contact-form-widget-2-3-1-sensitive-data-exposure-vulnerability?_s_id=cve -
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
Summary (en) Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget allows Retrieve Embedded Sensitive Data. This issue affects elfsight Contact Form widget: from n/a through 2.3.1. (en) Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget elfsight-contact-form allows Retrieve Embedded Sensitive Data.This issue affects elfsight Contact Form widget: from n/a through <= 2.3.1.

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Exposición de información sensible del sistema a una vulnerabilidad de esfera de control no autorizada en elfsight elfsight Contact Form widget permite recuperar datos sensibles incrustados. Este problema afecta al widget Formulario de contacto de Elfsight desde n/d hasta la versión 2.3.1.

09 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 16:15

Updated : 2026-04-23 15:27


NVD link : CVE-2025-31045

Mitre link : CVE-2025-31045

CVE.ORG link : CVE-2025-31045


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere