Contact Form to Email Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress plugin Contact Form to Email, version 1.3.24. This vulnerability allows authenticated attackers to inject malicious scripts by including script tags in the form name field. The injected JavaScript executes when other logged-in users access the form management page, potentially leading to session hijacking or credential theft.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the form management page.

Reproduction

To reproduce this vulnerability, log into WordPress and navigate to the Contact Form to Email plugin. Create a new form and enter a name that includes a script tag with JavaScript code, such as an alert. Once the form is published, the injected script will execute when the form management page is accessed by another logged-in user.

Added: May 10, 2026, 1:40 PM
Updated: May 10, 2026, 1:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
7.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.