Cross-Site Request Forgery in Cotonti's Contact Plugin
CVE-2026-93873
5.3MEDIUM
What is CVE-2026-93873?
Cotonti's contact plugin versions up to 1.0.0 lack proper validation for anti-CSRF tokens in its submission handling. This oversight enables attackers to exploit the vulnerability by submitting contact forms from rogue pages. Consequently, forged messages can be sent that appear to originate from authenticated users, leading to potential misuse of the contact function and unauthorized communication with the site's administrators.
Affected Version(s)
Cotonti 0 <= 1.0.0
