Description
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Scripting flaw found in the Ultimate Addons for Contact Form 7 WordPress plugin versions 3.5.45 and earlier. It allows attackers to inject arbitrary JavaScript into webpages delivered by the plugin, potentially enabling malicious content to be displayed to site visitors. The weakness is categorized as CWE-79.

Affected Systems

WordPress sites that have the Themefic Ultimate Addons for Contact Form 7 plugin installed with a version up to and including 3.5.45 are at risk. Sites running versions newer than 3.5.45, or those that do not use the plugin, are not affected.

Risk and Exploitability

The flaw carries a CVSS score of 7.1, signifying high severity, and an EPSS score of <1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. Because authentication is not required, an attacker can trigger the XSS by submitting a crafted request to a vulnerable endpoint, potentially from any web browser or automated script. The overall risk is moderate, but the impact could include malicious content injection on affected pages.

Generated by OpenCVE AI on August 3, 2026 at 15:38 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Addons for Contact Form 7 Plugin to the latest available version (at least 3.5.46).


OpenCVE Recommended Actions

  • Update the Ultimate Addons for Contact Form 7 plugin to version 3.5.46 or newer following the vendor's recommended update path.
  • If an immediate update is not possible, temporarily disable or uninstall the plugin to eliminate the attack surface.
  • Implement a strict Content Security Policy that blocks inline scripts and restricts script sources to trusted domains.

Generated by OpenCVE AI on August 3, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Themefic
Themefic ultimate Addons For Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Themefic
Themefic ultimate Addons For Contact Form 7
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
Title WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themefic Ultimate Addons For Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-28T14:54:16.153Z

Reserved: 2026-07-22T08:52:41.029Z

Link: CVE-2026-65439

cve-icon Vulnrichment

Updated: 2026-07-28T13:38:22.469Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T23:16:41.807

Modified: 2026-07-28T16:20:06.270

Link: CVE-2026-65439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')