WP Security
WWordPress Vulnerability Database

Hong Kong Security Alert Contact Form Flaw(CVE202512718)

  • byWP Security Vulnerability Report
  • January 19, 2026
  • No comments
  • 1 minute read
Broken Access Control in WordPress Quick Contact Form Plugin
0
Shares
0
0
0
0
Plugin Name WordPress Quick Contact Form Plugin
Type of Vulnerability Access control flaws
CVE Number CVE-2025-12718
Urgency Medium
CVE Publish Date 2026-01-19
Source URL CVE-2025-12718

Conversion Request — Next Step Required

I am ready to convert your blog into a Hong Kong security expert tone and produce clean HTML suitable for direct WordPress publishing. However, I don’t yet have the original blog content to convert. Please paste the blog text you want converted below, and I will:

  • Transform the language to a concise, authoritative Hong Kong security expert voice.
  • Remove any mentions or recommendations of WP-Firewall, Patchstack, or other WordPress security vendors.
  • Return complete HTML (no markdown or code fences) ready to paste into the WordPress editor.

Alternatively, if you would like me to draft a full blog post now about CVE-2025-12718 (WordPress Quick Contact Form Plugin — access control flaws), say “Draft new post” and I will create a Hong Kong security expert–tone article in HTML immediately.

Please paste the blog to convert, or reply “Draft new post” to proceed with a fresh article.

  • Tags:
  • WordPress Security
0 Shares:
Share 0
Tweet 0
Pin it 0
WP Security Vulnerability Report

— Previous article

Protecting User Data in WordPress Registrations(CVE202512825)

Next article —

Community Advisory LearnPress Access Control Flaw(CVE202514798)

You May Also Like
WWordPress Vulnerability Database

Hong Kong Security Alert Download Manager Access(CVE20262571)

  • March 21, 2026
Broken Access Control in WordPress Download Manager Plugin
WWordPress Vulnerability Database

Hong Kong Security Alert WordPress iFrame XSS(CVE20258089)

  • August 16, 2025
WordPress Advanced iFrame plugin <= 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
WWordPress Vulnerability Database

(CVE202549898)

  • August 15, 2025
WordPress School Management Plugin <= 93.2.0 - SQL Injection Vulnerability
WWordPress Vulnerability Database

Community Security Advisory Address Bar Ads XSS(CVE20261795)

  • February 17, 2026
Cross Site Scripting (XSS) in WordPress Address Bar Ads Plugin
WWordPress Vulnerability Database

Protect Donor Data from IDOR Exploits(CVE202610038)

  • June 9, 2026
Insecure Direct Object References (IDOR) in WordPress Charitable Plugin
WWordPress Vulnerability Database

Hong Kong Security NGO Alerts Templatera XSS(CVE202554747)

  • August 14, 2025
Plugin Name Templatera Type of Vulnerability XSS (Cross-Site Scripting) CVE Number CVE-2025-54747 Urgency Low CVE Publish Date 2025-08-14…
WP Security
© 2025 WP-Security.org Disclaimer: WP-Security.org is an independent, non-profit NGO community committed to sharing WordPress security news and information. We are not affiliated with WordPress, its parent company, or any related entities. All trademarks are the property of their respective owners.

Review My Order

0

Suggested for you

Subtotal

Taxes & shipping calculated at checkout

Checkout
0

Notifications

English
Chinese (Hong Kong) Chinese (China) Spanish Hindi French