CVE-2026-57708
Deferred Deferred - Pending Action

Cross-Site Scripting in Contact Form Entries Plugin

Vulnerability report for CVE-2026-57708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
crm_perks contact_form_entries to 1.5.2 (inc)
crm_perks contact_form_entries From 1.0.0 (inc) to 1.5.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross Site Scripting (XSS) flaw found in the WordPress Contact Form Entries Plugin, versions 1.5.2 and below. It occurs due to improper neutralization of input during web page generation, allowing attackers to inject malicious scripts into websites.

When exploited, these malicious scripts can execute in the browsers of visitors, potentially causing harmful effects such as redirects, displaying unwanted advertisements, or other malicious HTML payloads.

Exploitation requires user interaction, like clicking a malicious link or visiting a crafted page.

Detection Guidance

This vulnerability is a Reflected Cross Site Scripting (XSS) issue in the Contact Form Entries WordPress plugin versions 1.5.2 and below. Detection typically involves monitoring for suspicious HTTP requests that include malicious script payloads targeting the plugin's input fields.

While no specific commands are provided in the resources, common detection methods include using web application firewalls (WAF) with rules to detect XSS payloads, inspecting web server logs for unusual query parameters or POST data containing script tags, and using vulnerability scanners that target WordPress plugins for known XSS issues.

Impact Analysis

If exploited, this vulnerability can lead to attackers injecting malicious scripts that execute in the browsers of your website visitors.

  • Visitors may be redirected to malicious sites.
  • Unwanted advertisements or harmful content could be displayed.
  • It could be used in large-scale exploit campaigns targeting many websites.

Such impacts can damage your website's reputation, compromise user trust, and potentially lead to further security issues.

Compliance Impact

This vulnerability, a reflected Cross-Site Scripting (XSS) flaw, can impact compliance with standards and regulations like GDPR and HIPAA due to its potential to expose sensitive data or compromise user interactions.

  • GDPR: The vulnerability allows attackers to inject malicious scripts, which could lead to unauthorized access to personal data or session hijacking. Under GDPR, organizations must protect personal data from breaches, and failure to mitigate such vulnerabilities could result in non-compliance, fines, or legal action if user data is compromised.
  • HIPAA: If the affected plugin is used in a healthcare-related context (e.g., handling patient forms), the vulnerability could expose protected health information (PHI). HIPAA requires safeguards to protect PHI, and an XSS vulnerability that could lead to data exposure or unauthorized access may violate these requirements.

Additionally, the CVSS score of 7.1 indicates a medium-severity risk, which may require reporting under certain regulatory frameworks if the vulnerability is exploited or if it affects systems processing regulated data.

Mitigation Strategies

The immediate recommended step is to update the Contact Form Entries plugin to version 1.5.3 or later, where this vulnerability has been patched.

Until the update can be applied, it is advised to implement mitigation rules provided by Patchstack to block attacks exploiting this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart