Stored Cross-Site Scripting Vulnerability in Magic Tooltips for Contact Form 7 Plugin by WordPress
CVE-2026-101928
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-101928?
The Magic Tooltips For Contact Form 7 plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to inadequate input validation and output encoding. This flaw allows unauthenticated attackers to inject malicious scripts via the 'author' parameter. When an administrator accesses the comments section, the injected script is executed as the plugin's esc_html filter improperly decodes HTML-entity-encoded payloads. This results in the potential execution of arbitrary scripts on the website, compromising the security of users who visit compromised pages.
Affected Version(s)
Magic Tooltips For Contact Form 7 0 <= 1.0.34