Sceawere

Vulnerability Detail

CVE-2026-73379UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Contact Form Supsystic Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
supsystic
Product
Contact Form by Supsystic
Attack Type
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T15:17:05.867Z",
  "pubdate": "2026-08-18T15:17:05.867Z",
  "executiveSummary": "An unauthenticated bypass vulnerability has been identified in the Contact Form by Supsystic plugin, specifically affecting versions prior to 1.10.0. This security flaw enables remote attackers to bypass authentication controls and interact with internal plugin logic without requiring prior authorization or valid credentials. The vulnerability exposes the affected WordPress installations to unauthorized access vectors, potentially leading to unauthorized data manipulation or further exploitation depending on the underlying codebase exposure. Attackers require network access to the target WordPress site to exploit this flaw, leveraging the lack of proper authentication checks within the vulnerable component. Given that the vulnerability can be exploited by unauthenticated entities, the risk implication is significant for organizations relying on the affected versions. Remediation requires updating the Contact Form by Supsystic plugin to version 1.10.0 or later to ensure proper access controls and authentication enforcement are applied.",
  "technicalDetails": "The vulnerability resides in the Contact Form by Supsystic plugin for WordPress, impacting all versions strictly below 1.10.0. The root cause of the security defect stems from insufficient or absent authentication validation mechanisms within specific request handlers or endpoints exposed by the plugin. Specifically, the vulnerable component fails to verify whether incoming HTTP requests originate from authenticated users with appropriate privileges before executing sensitive functions or processing logic.\nFrom an attack flow perspective, an unauthenticated remote attacker can craft specialized HTTP requests targeting the vulnerable endpoints within the plugin. Because the application logic lacks proper session verification or capability checks, the server processes the incoming payload as if it originated from a legitimate, authorized user. Network exposure is broad, as these endpoints are typically accessible over standard HTTP/S protocols exposed to the internet by the WordPress environment.\nThe exploitation method relies on sending crafted requests directly to the affected plugin components without supplying any authentication tokens, cookies, or credentials. Depending on the exact codebase functionality exposed by the bypass, the payload behavior can facilitate unauthorized actions, functional access circumvention, or interaction with backend database queries and administrative routines typically restricted to privileged roles. Privilege requirements for exploitation are completely absent, allowing any anonymous network user to trigger the flaw.\nPost-exploitation impact involves the unauthorized execution of plugin-specific operations, which may serve as a stepping stone for broader system compromise, data leakage, or further integrity violations within the affected WordPress instance. The lack of robust input validation and access control enforcement compounds the severity of the flaw, making comprehensive source code updates essential for restoring security posture."
}
CVE-2026-73379: Contact Form Supsystic Bypass Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere