Executive brief
HT Contact Form 7 is a WordPress plugin used to create and manage website contact forms. A security vulnerability in this plugin allows attackers to inject malicious scripts into the website. If an administrator or visitor views the affected content, the script could redirect them to malicious sites, steal session information, or display unauthorized advertisements, potentially damaging the site's reputation and user security.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the HT Plugins HT Contact Form 7 plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows an unauthenticated remote attacker to inject malicious scripts into the application. Successful exploitation requires a privileged user (such as an administrator) to interact with the malicious payload, typically by viewing a crafted page or form submission in the plugin's interface. This can lead to the execution of arbitrary JavaScript in the context of the victim's browser session. The issue is resolved in version 2.8.3.
Affected products
- HT Plugins HT Contact Form 7 <= 2.8.2
Timeline
- 2026-04-20: disclosed: Reported by security researcher daroo
- 2026-05-20: patched: Version 2.8.3 released to address the vulnerability
- 2026-05-27: advisory: NVD and Patchstack published advisory details