Elfsight Contact Form Widget Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive system information in the Elfsight Contact Form widget for WordPress has been identified. This issue, which affects versions through 2.3.1, allows unauthorized users to retrieve embedded sensitive data that is typically not accessible to regular users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, potentially allowing for further exploitation of other weaknesses in the system.

Remediation

Users are advised to update the Elfsight Contact Form widget to a version later than 2.3.1. For those unable to update immediately, Patchstack offers a virtual patch that blocks attacks targeting this vulnerability.

Added: Jun 9, 2025, 4:57 PM
Updated: Jun 9, 2025, 4:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.