Sceawere
Vulnerability Detail
CVE-2026-100513UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CF7 Views Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Aman
- Product
- CF7 Views – Complete Entry Management for Contact Form 7
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:15.350Z",
"pubdate": "2026-09-30T13:17:15.350Z",
"executiveSummary": "The CF7 Views – Complete Entry Management for Contact Form 7 plugin, in versions 3.2.5 and below, contains a stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper neutralization of user-supplied input before rendering it within the administrative dashboard.\nA contributor-level authenticated attacker can exploit this vulnerability to inject malicious JavaScript into the application. When a privileged user, such as an administrator, views the affected entry management screens, the stored payload executes within the context of their session.\nSuccessful exploitation allows an attacker to perform actions on behalf of the administrator, potentially leading to unauthorized configuration changes, plugin settings modification, or the exfiltration of sensitive session cookies. Given that the impact is confined to the administrative interface, the risk is primarily associated with privileged account compromise and internal site administration integrity. Mitigation requires updating the plugin to a patched version or implementing strict input sanitization practices for contributor roles.",
"technicalDetails": "The vulnerability manifests as a stored Cross-Site Scripting (XSS) issue within the 'CF7 Views – Complete Entry Management for Contact Form 7' plugin. The root cause is the insufficient sanitization of input data provided by users with contributor-level privileges before that data is stored in the database and subsequently rendered in the administrative management interface.\nIn WordPress environments, the 'contributor' role generally lacks the capability to publish posts or execute arbitrary code. However, if the plugin allows these users to submit or interact with form entries that are not properly validated, they can inject malicious payloads into fields designed to store contact form data. When the plugin processes these entries for display, it fails to encode the output correctly, allowing the browser to interpret injected strings as executable HTML/JavaScript.\nThe attack flow proceeds as follows: First, a authenticated attacker with contributor access crafts a malicious payload, typically consisting of JavaScript wrapped in HTML tags such as <script> or event handlers like 'onerror' or 'onload'. Second, the attacker submits this payload through a form or interface managed by the plugin. Third, the plugin saves this input directly to the WordPress database without applying adequate output escaping (e.g., esc_html() or esc_js()). Fourth, an administrator navigates to the 'CF7 Views' entry management dashboard to review the submission. Finally, when the dashboard page loads the stored data, the browser executes the injected script within the administrator's authenticated session.\nThe scope of this vulnerability is limited to the WordPress administrative backend. Because the payload executes within the administrative session, the attacker can leverage the administrator’s permissions to perform high-privilege actions, such as creating new administrative accounts, modifying plugin settings, or triggering further server-side operations through forged administrative requests (CSRF). Since the vulnerability relies on the stored nature of the data, the payload persists until the entry is deleted or the malicious database record is manually purged. The attack requires the attacker to have at least 'contributor' level access to the WordPress site, making this an authenticated vulnerability rather than a public-facing unauthenticated entry point."
}