Executive brief
The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to a security flaw that could allow an attacker to execute malicious scripts in a user's browser. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions, data theft, or redirection to malicious websites. The plugin is used to manage and filter messages sent through the popular Contact Form 7 tool.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Kofi Mokome Message Filter for Contact Form 7 (cf7-message-filter) plugin for WordPress. The vulnerability stems from the improper neutralization of user-supplied input during web page generation, allowing an attacker to inject malicious scripts. The attack vector is network-based and requires no special privileges, though it does necessitate user interaction (e.g., a victim clicking a malicious link). Successful exploitation allows the execution of arbitrary HTML or JavaScript payloads in the victim's browser, which can lead to session hijacking or unauthorized administrative actions. The issue affects all versions up to and including 1.6.3.8 and is fixed in version 1.6.3.9.
Affected products
- Kofi Mokome Message Filter for Contact Form 7 n/a through 1.6.3.8
Timeline
- 2026-06-03: disclosed: Reported by dutafi
- 2026-07-08: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE-2026-57423
- 2026-07-13: patched: Version 1.6.3.9 released