Izuchy · Contact Form 7 With Chatwork · CVE-2025-13975
**Name of the Vulnerable Software and Affected Versions**
Contact Form 7 with ChatWork versions prior to 1.1.1
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with administrator-level access can inject arbitrary web scripts through the `api token` and `roomid` settings. These scripts execute when a user accesses the settings page. This issue specifically affects multi-site installations and environments where `unfiltered html` has been disabled.
**Recommendations**
Update to a version newer than 1.1.0.
Restrict access to the `api token` and `roomid` settings to minimize the risk of exploitation.