Junglewise Threat Intelligence

CVE-2026-15735: itpathsolutions Contact Form to Any API Stored XSS in cf7anyapi_form_field

CVE-2026-15735 · Severity: medium · CVSS 6.4 · Published 2026-07-29

Executive brief

The Contact Form to Any API plugin for WordPress, which allows website owners to send form submissions to external services, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'cf7anyapi_form_field' post meta. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into the database. These scripts are then executed in the context of a user's browser whenever they visit the compromised page. The issue exists in all versions up to and including 3.0.6. A patch has been identified in recent changesets, and users should update to the latest version.

Affected products

  • itpathsolutions Contact Form to Any API up to, and including, 3.0.6

Timeline

  • 2026-07-29: advisory: NVD publication date

References