CVE-2025-1382Patch(lordlinus / contact_us)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lordlinus contact_us systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • contact_us

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
contact_us

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-10: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-10: 102-10
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-1382 : CONTACT US BY LORD LINUS WORDPRESS PLUGIN CSRF → STORED XSS CHAIN ALERT 🚨 WordPress A critical CSRF to stored XSS vulnerability chain has been disclosed in the Contact Us By Lord Linus WordPress plugin, allowing attackers to achieve persistent administrative compromise through social engineering. Public proof-of-concept is available and mass exploitation is highly likely. Risk Severity: High (admin takeover, persistent XSS, public PoC, rapid exploitation expected) Impact: • Persistent JavaScript execution in WordPress admin context • Full WordPress administrative takeover • Session hijacking via stolen cookies and nonces • Malicious plugin and theme installation • Database exfiltration and malware injection • Downstream compromise of site visitors • Severe GDPR, PCI-DSS, and brand reputation impact Root Cause: CWE-352 (Cross-Site Request Forgery) + CWE-79 (Stored Cross-Site Scripting) Missing nonce validation and improper input sanitization in plugin admin workflows allow attackers to inject persistent JavaScript via forged admin requests. Attackers can: • Craft malicious HTML forms containing JavaScript payloads • Trick authenticated administrators into submitting forged requests • Inject persistent stored XSS into plugin settings • Execute arbitrary JavaScript in admin sessions • Hijack sessions and escalate privileges • Achieve full WordPress site takeover Are You Affected? Vulnerable: • Contact Us By Lord Linus plugin ≤ 2.6 Fixed in: • Version 2.7 (released February 10, 2026) Immediate Action Required: Update/Patch: • Upgrade immediately to Contact Us By Lord Linus v2.7 or later Mitigation (if you cannot patch immediately): • Restrict /wp-admin access to trusted IP ranges • Enforce VPN-only or SSO-protected admin access • Deploy WAF rules blocking POST requests to vulnerable plugin endpoints • Enable strict Content Security Policy for admin panel Audit & Monitor: • Review logs for suspicious POST requests to admin.php?page=contact-us-lord-linus-settings • Query wp_options for injected script payloads • Monitor for unauthorized plugin installations and privilege changes • Review wp_usermeta for suspicious role modifications Incident Response: • If compromise is suspected, immediately terminate all admin sessions, rotate WordPress salts, preserve wp_options for forensics, inspect for hidden admin accounts, and assume persistent compromise occurred Given WordPress’s massive attack surface and rapid exploitation of plugin flaws, this CSRF → stored XSS chain should be treated as a site takeover event, patch immediately and hunt for compromise. 🛡️ #ostorlabCVE

    Post summary

    This advisory discloses a critical CSRF‑to‑Stored XSS chain in the Contact Us By Lord Linus WordPress plugin, provides a public PoC, and urges immediate upgrade to v2.7 with additional mitigation steps.

    0000074
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applordlinuscontact_us-wordpress-

Explore more