Reflected XSS Vulnerability in 299Ko Contact Form Plugin
CVE-2026-71249

6.1MEDIUM

Key Information:

Vendor

299ko

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71249?

The 299Ko Contact Form Plugin has a vulnerability that allows unauthenticated attackers to exploit the lack of sanitization in the input fields of the public contact form. When users submit data through the form, the plugin directly inserts this data into the page template without proper encoding or escaping techniques. This oversight permits attackers to inject malicious scripts using payloads that may execute when the form is viewed by users, including administrators, thereby posing a significant risk of session hijacking and unauthorized access.

Affected Version(s)

299Ko 0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Javokhir Tursunboyev
.