Description
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the plugin's esc_html filter callback decodes HTML-entity-encoded payloads (e.g. those containing '<tip>') back into live HTML, meaning an entity-encoded script payload submitted as a comment author name — which bypasses sanitize_text_field — is rendered as executable markup when an administrator views wp-admin/edit-comments.php.
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross-Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The Magic Tooltips For Contact Form 7 plugin is vulnerable to stored cross‑site scripting because the esc_html filter callback decodes HTML‑entity‑encoded payloads, allowing an attacker to submit a comment author name containing an encoded script. The stored author name is rendered as executable markup when an administrator views comments, enabling arbitrary code execution in the context of wp‑admin. This flaw is a classic client‑side injection (CWE‑79).

Affected Systems

Magic Tooltips For Contact Form 7 plugin for WordPress versions up to and including 1.0.34.

Risk and Exploitability

The vulnerability can be triggered by any unauthenticated user who can add a comment, since the comment author field is not sanitized. The exploit requires only writing a comment with an entity‑encoded script; no special privileges or user interaction are needed beyond an administrator viewing the stored comment. The CVSS base score of 7.2 indicates a high severity. Because the exploit is straightforward and no EPSS score is available, the likelihood of exploitation is uncertain, but the known use of the author field suggests that attackers can easily craft payloads. The vulnerability is not listed in the CISA KEV catalog, but it remains a serious risk for sites using the plugin.

Generated by OpenCVE AI on October 3, 2026 at 06:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest plugin version (1.0.35 or newer).
  • If the plugin is no longer required, uninstall it completely.
  • If an update cannot be performed immediately, block or sanitize the comment author field to remove entity encoding and prevent stored script payloads.

Generated by OpenCVE AI on October 3, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the plugin's esc_html filter callback decodes HTML-entity-encoded payloads (e.g. those containing '&lt;tip&gt;') back into live HTML, meaning an entity-encoded script payload submitted as a comment author name — which bypasses sanitize_text_field — is rendered as executable markup when an administrator views wp-admin/edit-comments.php.
Title Magic Tooltips For Contact Form 7 <= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:44.749Z

Reserved: 2026-09-28T16:15:22.184Z

Link: CVE-2026-101928

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:21.243Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:40.080

Modified: 2026-10-03T16:16:32.233

Link: CVE-2026-101928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')