CVE-2026-8172
Description
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Simple Basic Contact Form | — | 0 ≤ 20250114 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-79 Cross-Site Scripting (XSS) |