Executive brief
The Contact Form to Any API plugin for WordPress, which allows website owners to send form submissions to external services, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'cf7anyapi_form_field' post meta. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into the database. These scripts are then executed in the context of a user's browser whenever they visit the compromised page. The issue exists in all versions up to and including 3.0.6. A patch has been identified in recent changesets, and users should update to the latest version.
Affected products
- itpathsolutions Contact Form to Any API up to, and including, 3.0.6
Timeline
- 2026-07-29: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/tags/3.0.6/admin/class-cf7-to-any-api-admin.php
- https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/tags/3.0.6/admin/class-cf7-to-any-api-admin.php
- https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/tags/3.0.6/admin/class-cf7-to-any-api-admin.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3624000%40contact-form-to-any-api&new=3624000%40contact-form-to-any-api
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1f5390b1-c85b-4bf6-ab38-6ae0efe72ffa?source=cve