Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Reflected XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.36.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Contact Form by Supsystic plugin fails to properly neutralize user‑supplied input before rendering it, allowing an attacker to inject malicious JavaScript that executes in the victim’s browser when a reflected input is displayed. This reflected XSS flaw, classified as CWE‑79, could enable attackers to steal session cookies, modify page content, or redirect users to malicious sites, compromising confidentiality and integrity of user data but not directly causing denial of service or full system compromise.

Affected Systems

WordPress sites that have installed the Contact Form by Supsystic plugin version 1.7.36 or earlier are affected. Any such deployment of the plugin on a publicly accessible WordPress site can leverage the vulnerable form endpoint, granting the flaw to any user who can access the form or the vulnerable URL.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Attackers can exploit it through a browser‑based vector, typically by crafting a malicious link or form that includes injected code; when an end user visits the link or submits the form, the script runs in their context. Because reflected XSS can be triggered by a simply crafted payload, the risk remains real for sites that expose the vulnerable form to external traffic.

Generated by OpenCVE AI on April 29, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Contact Form by Supsystic plugin to the latest version (1.7.37 or newer).
  • If an immediate update is not possible, remove or disable the plugin entirely or block access to its endpoints to stop user interaction.
  • Apply a strict Content Security Policy that limits script execution to trusted sources, which can mitigate the impact of any remaining XSS payloads.

Generated by OpenCVE AI on April 29, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Reflected XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.35. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Reflected XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.36.
Title WordPress Contact Form by Supsystic plugin <= 1.7.35 - Cross Site Scripting (XSS) vulnerability WordPress Contact Form by Supsystic plugin <= 1.7.36 - Cross Site Scripting (XSS) vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Supsystic
Supsystic contact Form
Wordpress
Wordpress wordpress
Vendors & Products Supsystic
Supsystic contact Form
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Reflected XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.35.
Title WordPress Contact Form by Supsystic plugin <= 1.7.35 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Supsystic Contact Form
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:04:48.262Z

Reserved: 2025-06-19T10:02:55.535Z

Link: CVE-2025-52753

cve-icon Vulnrichment

Updated: 2025-10-23T15:21:24.964Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:45.190

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-52753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T21:15:16Z

Weaknesses