CVE-2026-81300
nicheUnauthenticated XSS in Calculation For Contact Form 7 WordPress plugin
Cross-site scripting (CWE-79) in the WordPress plugin Calculation For Contact Form 7 affects all versions up to and including 1.0 and can be triggered by an unauthenticated remote attacker, consistent with the CVSS vector (AV:N, AC:L, PR:N, UI:R, S:C). The payload executes in the browser of a user who interacts with the affected page or form output, meaning the victim is typically an administrator or visitor rather than the attacker. Successful exploitation runs attacker-controlled JavaScript with the victim's privileges, which can be used to steal session cookies or perform actions on the victim's behalf, although the low confidentiality/integrity/availability ratings indicate limited per-incident impact. Any WordPress site running the plugin at version 1.0 or earlier is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days (8th percentile), so there are no confirmed reports of in-the-wild exploitation.
What to do: Upgrade Calculation For Contact Form 7 to the first release newer than 1.0 as soon as the vendor publishes a patched version, and verify the fixed version on the plugin's listing or changelog before deploying. Until a fix is available, consider deactivating the plugin on internet-facing sites or applying WAF rules against script payloads in form input. Administrators should also review existing pages and form output for unexpected injected scripts.
| Calculation For Contact Form 7 (WordPress plugin) | <= 1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.