Description
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Message Filter for Contact Form 7 plugin contains an unauthenticated cross‑site scripting flaw that permits an attacker to embed malicious JavaScript in form fields. When a legitimate user submits data, the plugin fails to properly sanitize input, causing the attacker’s script to execute within the victim’s browser session. This can lead to credential theft, session hijacking, or defacement of the website experience.

Affected Systems

WordPress installations that use the Message Filter for Contact Form 7 plugin version 1.6.3.9 or earlier. The vulnerability applies to all instances where the plugin is active on public contact forms.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as a high‑severity vulnerability. The EPSS score of <1% indicates a very low but nonzero probability that the flaw is being actively exploited, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread documented exploitation yet. An attacker can exploit this flaw simply by submitting crafted input via any exposed contact form, with no authentication or privileged access required.

Generated by OpenCVE AI on August 3, 2026 at 15:38 UTC.

Remediation

Vendor Solution

Update the WordPress Message Filter for Contact Form 7 Plugin to the latest available version (at least 1.6.4.0).


OpenCVE Recommended Actions

  • Update the WordPress Message Filter for Contact Form 7 plugin to version 1.6.4.0 or newer.
  • Disable or remove the plugin from any WordPress sites where an immediate upgrade is not feasible until the patch is applied.
  • After updating, review the plugin’s configuration to ensure no custom HTML or JavaScript is allowed in form fields and enforce strict input sanitization.

Generated by OpenCVE AI on August 3, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Kofimokome
Kofimokome message Filter For Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Kofimokome
Kofimokome message Filter For Contact Form 7
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
Title WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Kofimokome Message Filter For Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-28T13:35:00.094Z

Reserved: 2026-07-22T08:52:41.029Z

Link: CVE-2026-65438

cve-icon Vulnrichment

Updated: 2026-07-28T13:34:50.934Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T23:16:41.673

Modified: 2026-07-28T16:19:12.780

Link: CVE-2026-65438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')