Junglewise Threat Intelligence

CVE-2026-65438: Kofi Mokome Message Filter for Contact Form 7 unauthenticated XSS

CVE-2026-65438 · Severity: high · CVSS 7.1 · Published 2026-07-27

Executive brief

A security vulnerability exists in the Message Filter for Contact Form 7 plugin, which is used to manage and filter messages sent through WordPress contact forms. An attacker could use this flaw to inject malicious scripts into the website, which would then execute in the browser of other users, such as site administrators. This could lead to unauthorized actions being performed on the site, redirection to malicious websites, or the theft of sensitive session information.

Technical details

The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS) in versions up to and including 1.6.3.9. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated attacker can exploit this by tricking a user (typically an administrator) into clicking a specially crafted link or visiting a malicious page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized site modifications. The issue is resolved in version 1.6.4.0.

Affected products

  • Kofi Mokome Message Filter for Contact Form 7 <= 1.6.3.9

Timeline

  • 2026-06-26: disclosed: Reported by dutafi to Patchstack
  • 2026-07-27: advisory: Published by Patchstack and NVD
  • 2026-07-27: patched: Version 1.6.4.0 released to address the vulnerability

References

Related threats