Junglewise Threat Intelligence

CVE-2026-57379: WPPOOL FormyChat stored XSS in social-contact-form

CVE-2026-57379 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

WPPOOL FormyChat, a WordPress plugin used for adding social contact forms to websites, contains a security flaw that allows attackers to inject malicious scripts. If an administrator or visitor views a page containing this injected content, the attacker's script will execute in their browser. This could lead to unauthorized actions, theft of session cookies, or redirection to malicious websites, potentially compromising the site's integrity and user data.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the WPPOOL FormyChat (social-contact-form) plugin for WordPress due to insufficient sanitization of user-supplied input. An unauthenticated remote attacker can inject malicious JavaScript into the application, which is then stored on the server. The vulnerability is triggered when a victim (typically a site administrator) views the affected page or form submission. Successful exploitation allows the attacker to execute arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 2.15.4.

Affected products

  • WPPOOL FormyChat (social-contact-form) <= 2.15.3

Timeline

  • 2026-05-16: disclosed: Reported by dodoh4t
  • 2026-07-07: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published date

References