Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation, also known as Reflected Cross‑Site Scripting. When input is submitted through the Contact Form Entries plugin, the data is reflected back to the page without adequate sanitization, which allows an attacker to deliver and execute arbitrary JavaScript in the victim’s browser. This flaw enables the execution of client‑side code originating from user input.

Affected Systems

The affected product is the WordPress plugin Contact Form Entries by CRM Perks. All releases from the initial revision through version 1.5.2 are impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level. The EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could send or embed a malicious payload that is reflected by the plugin and then executed in the victim’s browser when the page is viewed.

Generated by OpenCVE AI on August 1, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Contact Form Entries plugin to a version that removes the XSS flaw as soon as an update is available.
  • If the plugin is not required for site functionality, disable it or delete the installed plugin to eliminate the attack surface.
  • Deploy a Web Application Firewall rule or a Content Security Policy that restricts the execution of script content to trusted sources as a temporary mitigation pending a patch.

Generated by OpenCVE AI on August 1, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Crmperks
Crmperks contact Form Entries
Wordpress
Wordpress wordpress
Vendors & Products Crmperks
Crmperks contact Form Entries
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.
Title WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crmperks Contact Form Entries
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:31:13.641Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57708

cve-icon Vulnrichment

Updated: 2026-07-13T13:31:10.757Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')