Description
The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidential data disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Contact Form to Chat Apps plugin allows unauthenticated users to retrieve any form submission that has been created using Gravity Forms or other supported third‑party form integrations. Because the formychat_get_gf_entry AJAX action does not verify capability, nonce or session data, an attacker can craft a request to the endpoint and read sensitive fields such as names, email addresses and custom data. This results in a loss of confidentiality for all data collected through the plugin. The weakness is identified as information disclosure (CWE‑200).

Affected Systems

Any WordPress site that has the Contact Form to Chat Apps plugin older than 2.15.8 with Gravity Forms or compatible form providers enabled is at risk. The vulnerability is independent of the user’s role because no authentication is checked.

Risk and Exploitability

The CVSS score of 5.3 classifies the flaw as moderate severity. The EPSS score of 0.00206 indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation yet. However, the lack of authentication and public AJAX endpoint makes the attack trivial for any internet‑reachable user; an attacker can issue an unauthenticated HTTP request to the plugin’s endpoint and obtain the form entries without further prerequisites.

Generated by OpenCVE AI on September 15, 2026 at 17:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Contact Form to Chat Apps plugin to version adds the missing authentication, disable the formychat_get_gf_entry AJAX action through a plugin setting, a custom code snippet, or by blocking the endpoint with a web‑application firewall.
  • Restrict access to the plugin’s AJAX endpoints to authenticated users, IP ranges, or specific user agents to limit exposure.
  • Review stored form submissions for exposed data and remove any sensitive information that may have been inadvertently disclosed.

Generated by OpenCVE AI on September 15, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 13 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 13 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.
Title Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-13T10:46:08.729Z

Reserved: 2026-08-21T11:01:36.070Z

Link: CVE-2026-77773

cve-icon Vulnrichment

Updated: 2026-09-13T10:42:39.187Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T06:16:24.680

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-77773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor