Sceawere
Vulnerability Detail
CVE-2026-39745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Contact Form
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- bestweblayout
- Product
- Contact Form to DB by BestWebSoft
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:45.730Z",
"pubdate": "2026-10-06T09:17:45.730Z",
"executiveSummary": "The Contact Form to DB plugin for WordPress, specifically versions 1.7.6 and earlier, contains an unauthenticated Cross-Site Scripting (XSS) vulnerability. This flaw resides within the plugin's data handling processes for submitted contact forms.\nThe vulnerability allows an unauthenticated, remote attacker to inject malicious JavaScript payloads into form fields that are subsequently stored in the database.\nWhen an administrator or authorized user views the submitted data via the WordPress dashboard, the malicious script is rendered by their browser within the context of the administrative session.\nSuccessful exploitation can lead to unauthorized actions, session hijacking, credential theft, or the injection of persistent malicious content into the site.\nBecause the vulnerability is unauthenticated, it presents a significant risk, as no prior access to the WordPress application is required to initiate an attack.",
"technicalDetails": "The vulnerability is a stored Cross-Site Scripting (XSS) flaw occurring within the 'Contact Form to DB' plugin version 1.7.6 and below. The root cause is the insufficient sanitization and improper escaping of user-supplied input submitted through the plugin's contact form before the data is stored in the database and subsequently rendered in the administrative interface.\nThe attack flow begins when an unauthenticated attacker submits a contact form containing a malicious JavaScript payload (e.g., <script>alert(document.cookie)</script>) within one of the input fields, such as 'Name', 'Subject', or 'Message'.\nThe plugin fails to sanitize this input, allowing the script to be saved directly into the WordPress database table used by the plugin to track submissions.\nThe vulnerability is triggered when an administrator navigates to the plugin's submissions management page in the WordPress dashboard. The plugin retrieves the stored, malicious data and echoes it directly into the HTML document without appropriate output encoding.\nUpon loading the submissions page, the attacker's script executes within the context of the administrator's authenticated session. This grants the attacker the ability to perform actions on behalf of the administrator, such as creating new administrative users, modifying plugin settings, or redirecting the user to malicious sites.\nBecause the payload is persistent, the script will execute every time the administrative dashboard view is accessed until the malicious entry is manually removed from the database.\nThis vulnerability is classified as stored XSS due to the persistence of the payload in the database. It is highly dangerous as it bypasses traditional authentication controls by leveraging the inherent trust the application places in administrative sessions."
}