Sceawere
Vulnerability Detail
CVE-2026-40807UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CF7 Views Unauthenticated XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- Aman
- Product
- CF7 Views – Complete Entry Management for Contact Form 7
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:53.287Z",
"pubdate": "2026-10-06T09:17:53.287Z",
"executiveSummary": "A critical security vulnerability has been identified in the CF7 Views - Complete Entry Management for Contact Form 7 WordPress plugin, affecting all versions up to and including 3.2.6. This vulnerability is classified as Unauthenticated Cross-Site Scripting (XSS), which allows remote, unauthenticated attackers to inject malicious scripts into web pages served by the affected application.\nBecause the exploit requires no authentication, any external actor can target the application without possessing valid credentials. The primary risk associated with this vulnerability is the execution of arbitrary JavaScript code within the context of an unsuspecting user's browser session. Depending on the privileges of the victim, this execution can lead to severe security compromises, including the theft of session cookies, session hijacking, unauthorized administrative actions, site defacement, and the redirection of users to malicious external domains. This vulnerability poses a significant risk to organizations utilizing the affected plugin versions, as it undermines the integrity and confidentiality of user interactions with the WordPress site. Immediate remediation is required to mitigate the threat of exploitation.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization of user-supplied input and the subsequent lack of proper output encoding within the CF7 Views - Complete Entry Management for Contact Form 7 plugin. In versions 3.2.6 and prior, the plugin fails to adequately sanitize or validate parameters processed during public-facing operations or administrative views. When a user submits data—potentially through form entries or specifically crafted HTTP requests—the application processes this input and stores or reflects it without sanitizing malicious HTML tags or JavaScript payloads. Because the flaw is unauthenticated, an external attacker can craft a payload containing malicious JavaScript and submit it directly to the application.\nThe attack flow begins with the threat actor identifying an active installation of the CF7 Views plugin running version 3.2.6 or lower. The attacker constructs a malicious payload, typically involving script tags or event handlers embedded in HTML elements. Since no authentication is required, the attacker submits this payload via a request that the plugin processes—either as a form submission entry meant for display or as a direct request parameter that is reflected in the application's response. Once the payload is stored or rendered within the application's user interface, it awaits execution. When a victim, such as a site administrator, views the compromised entry or accesses the affected page, the browser interprets the unsanitized payload as executable code rather than plain text.\nThe execution of the injected script occurs entirely within the context of the victim's active browser session. If an administrative user triggers the payload, the attacker can leverage the browser's trusted state to perform unauthorized administrative operations. This includes creating new rogue administrator accounts, modifying site configurations, installing malicious plugins, or extracting sensitive application data. For standard users, the impact ranges from session hijacking through the exfiltration of session tokens stored in cookies or local storage, to forced redirection to phishing websites. Because the vulnerability requires zero privileges to exploit, it represents a low-complexity vector that can be automated by attackers seeking to compromise vulnerable WordPress environments at scale."
}