Executive brief
Ultimate Addons for Contact Form 7 is a WordPress plugin that extends the functionality of the popular Contact Form 7 tool. A security vulnerability in this plugin allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could redirect users to malicious sites, display unauthorized advertisements, or potentially hijack user sessions.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Ultimate Addons for Contact Form 7 plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a privileged user) to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction required). Successful exploitation can lead to unauthorized script execution in the context of the victim's browser, potentially resulting in session theft or site defacement. The issue is resolved in version 3.5.46.
Affected products
- Themefic Ultimate Addons for Contact Form 7 <=3.5.45
Timeline
- 2026-06-27: disclosed: Reported by Nguyen Ba Khanh
- 2026-07-27: advisory
- 2026-07-27: patched: Version 3.5.46 released to address the vulnerability