Description
Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Cross-site scripting (XSS)
Action: Patch
AI Analysis

Impact

A contributor cross‑site scripting flaw exists in WordPress CF7 Views – Complete Entry Management for Contact Form 7 versions 3.2.5 and earlier, allowing malicious users with contributor privileges to inject arbitrary JavaScript into the plugin’s output. The vulnerability is a classic broken input validation issue (CWE‑79) that can compromise the integrity of web pages, steal session cookies, or deface site content.

Affected Systems

The affected product is the WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin, specifically all releases up to and including 3.2.5. Any WordPress installation that has this plugin installed and not upgraded to 3.2.6 or newer is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate impact level. No EPSS or KEV listing is available, suggesting limited publicly known exploitation. Because the flaw requires contributor or higher privileges, the attack vector is likely authenticated rather than remote. An attacker who gains contributor access can embed harmful scripts that will run in the context of users who view the affected pages, potentially leading to data theft or defacement. The overall risk is moderate, focused on accounts that can submit or edit form entries.

Generated by OpenCVE AI on September 30, 2026 at 15:29 UTC.

Remediation

Vendor Solution

Update the WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin to the latest available version (at least 3.2.6).


OpenCVE Recommended Actions

  • Apply the latest plugin update (v3.2.6 or newer).
  • If an update cannot be applied immediately, temporarily disable the plugin or revoke contributor privileges to block exploitation.
  • Review and sanitize existing stored form entries to remove any injected scripts.

Generated by OpenCVE AI on September 30, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Title WordPress CF7 Views &#8211; Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:37:19.781Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100513

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:15.350

Modified: 2026-09-30T14:17:22.287

Link: CVE-2026-100513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:30:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')