CVE-2025-13975 | izuchy Contact Form 7 with ChatWork Plugin up to 1.1.0 on WordPress Setting api_token/roomid cross site scripting
A vulnerability was found in izuchy Contact Form 7 with ChatWork Plugin up to 1.1.0 on WordPress. It has been rated as problematic. This vulnerability affects unknown code of the component Setting Handler. The manipulation of the argument api_token/roomid leads to cross site scripting.
This vulnerability is traded as CVE-2025-13975. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.