Junglewise Threat Intelligence

CVE-2026-39449: Contact Form to Any API unauthenticated XSS

CVE-2026-39449 · Severity: high · CVSS 7.1 · Published 2026-06-15

Executive brief

The Contact Form to Any API plugin for WordPress, which connects website forms to external services, contains a security flaw that allows attackers to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link or form, the attacker could steal session information, redirect users to malicious websites, or deface the site. No official fix has been released by the developer at this time.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Contact Form to Any API plugin for WordPress (versions <= 3.0.3) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is unauthenticated, meaning an attacker does not need an account on the target system to initiate the attack. However, successful exploitation requires user interaction, such as a privileged user clicking a malicious link. This can lead to the execution of arbitrary JavaScript in the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. As of the advisory date, no official patch is available.

Affected products

  • Contact Form to Any API Contact Form to Any API <= 3.0.3

Timeline

  • 2026-03-18: other: Vulnerability reported by 0xManticore
  • 2026-04-22: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published in NVD

References