Stored Cross-Site Scripting Vulnerability in Magic Tooltips for Contact Form 7 Plugin by WordPress
CVE-2026-101928

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

What is CVE-2026-101928?

The Magic Tooltips For Contact Form 7 plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input validation and output encoding. This flaw allows unauthenticated attackers to inject malicious scripts via the 'author' parameter. When an administrator accesses the comments section, the injected script is executed as the plugin's esc_html filter improperly decodes HTML-entity-encoded payloads. This results in the potential execution of arbitrary scripts on the website, compromising the security of users who visit compromised pages.

Affected Version(s)

Magic Tooltips For Contact Form 7 0 <= 1.0.34

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Afifudin Maarif
.