Back to overview

CVE-2026-8172

Description
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.

Metadata

CVE ID
CVE-2026-8172
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-08 13:53 UTC
Published
2026-06-23 06:00 UTC
Last updated
2026-06-23 06:00 UTC
Vendor / Product
Unknown / Simple Basic Contact Form
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Simple Basic Contact Form 0 ≤ 20250114
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
Back to overview