Junglewise Threat Intelligence

CVE-2026-57411: Aman CF7 Views DOM-based XSS in Complete Entry Management for Contact Form 7

CVE-2026-57411 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

A security vulnerability exists in the CF7 Views plugin for WordPress, which is used to manage and display Contact Form 7 entries. An attacker could use this flaw to execute malicious scripts in the browser of a site visitor or administrator, potentially leading to unauthorized actions or the theft of sensitive session information. This occurs when a user interacts with a specially crafted link or page created by the attacker.

Technical details

The Aman CF7 Views – Complete Entry Management for Contact Form 7 plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. The flaw exists in versions up to and including 3.2.2. An unauthenticated remote attacker can exploit this by tricking a user into visiting a crafted URL or interacting with a malicious page element. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to bypass same-origin policies or perform actions on behalf of the user. The issue is addressed in version 3.2.3.

Affected products

  • Aman CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.2

Timeline

  • 2026-05-08: other: Vulnerability reported by ParkHyunWoo
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD

References