Quick Contact Form WordPress Plugin Open Mail Relay Vulnerability

Vulnerability

A vulnerability allowing open mail relay has been identified in the Quick Contact Form plugin for WordPress, affecting all versions through 8.2.6. The issue arises from the 'qcf_validate_form' AJAX endpoint, which permits user-controlled parameters to dictate the 'from' email address. This flaw enables unauthenticated attackers to send emails to arbitrary recipients via the server, using details from the contact form submission.

Impact

Exploitation of this vulnerability allows for unauthorized email transmission to any recipient, using the server's resources.

Remediation

Users are advised to update the Quick Contact Form plugin to version 8.2.7 or a newer patched version.

Added: Jan 17, 2026, 3:21 AM
Updated: Jan 17, 2026, 3:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
0.0
relevance
2.1
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.