Junglewise Threat Intelligence

CVE-2026-57708: CRM Perks Contact Form Entries reflected XSS

CVE-2026-57708 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

CRM Perks Contact Form Entries, a WordPress plugin used to manage and store form submissions, is vulnerable to a security flaw that allows attackers to execute malicious scripts. By tricking a site administrator or user into clicking a specially crafted link, an attacker can hijack sessions, redirect visitors to malicious websites, or deface the site. This issue impacts all versions up to and including 1.5.2.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the CRM Perks Contact Form Entries plugin for WordPress (versions <= 1.5.2). The vulnerability stems from the improper neutralization of user-supplied input during web page generation, allowing an attacker to inject malicious scripts. An unauthenticated attacker can exploit this by crafting a malicious URL and inducing a user (typically an administrator) to interact with it. Successful exploitation results in the execution of arbitrary JavaScript in the victim's browser, which can lead to session hijacking or unauthorized actions. The issue is addressed in version 1.5.3.

Affected products

  • CRM Perks Contact Form Entries <= 1.5.2

Timeline

  • 2026-06-20: disclosed: Reported by daroo to Patchstack
  • 2026-07-10: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • patched: Fixed in version 1.5.3

References