← Retour aux CVEs
CVE-2025-13973
MEDIUM5.3
Description
The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.0.2. The plugin stores spam detection logs at a predictable publicly accessible location (wp-content/uploads/stickeasy-protected-contact-form/spcf-log.txt). This makes it possible for unauthenticated attackers to download the log file and access sensitive information including visitor IP addresses, email addresses, and comment snippets from contact form submissions that were flagged as spam.
Details CVE
Score CVSS v3.15.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie2/14/2026
Derniere modification2/18/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-200
References
https://plugins.trac.wordpress.org/browser/stickeasy-protected-contact-form/tags/1.0.0/stickeasy-protected-contact-form.php#L157(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/stickeasy-protected-contact-form/trunk/stickeasy-protected-contact-form.php#L157(security@wordfence.com)
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3425729%40stickeasy-protected-contact-form&new=3425729%40stickeasy-protected-contact-form(security@wordfence.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.