Stored Cross-Site Scripting Vulnerability in Contact Form to DB Plugin for WordPress
CVE-2026-13359

7.2HIGH

What is CVE-2026-13359?

The Contact Form to DB by BestWebSoft plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output escaping. This vulnerability arises from the cntctfrm_contact_dropdown parameter across all versions up to and including 1.7.5. Attackers can leverage this flaw to inject malicious scripts into pages accessed by users. When an administrator visits the message manager page, these scripts execute within their browser session, potentially leading to unauthorized access and session hijacking through a simple contact form submission.

Affected Version(s)

Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress 0 <= 1.7.5

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.