CVE-2025-12718 | Quick Contact Form Plugin up to 8.2.6 on WordPress AJAX Endpoint qcf_validate_form from access control (EUVD-2026-3160)
A vulnerability was found in Quick Contact Form Plugin up to 8.2.6 on WordPress. It has been classified as critical. Impacted is the function qcf_validate_form of the component AJAX Endpoint. Performing a manipulation of the argument from results in improper access controls.
This vulnerability is reported as CVE-2025-12718. The attack is possible to be carried out remotely. No exploit exists.