SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81300

HIGH · CVSS 7.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit a Cross Site Scripting (XSS) flaw in Calculation For Contact Form 7 versions 1.0 and earlier, potentially leading to the execution of arbitrary scripts in the context of a user's session. This can compromise user data and session integrity, making it critical for organizations using this plugin to prioritize remediation. Web developers and administrators managing sites with this plugin should take immediate action to update or mitigate the risk.

CVE
CVE-2026-81300
Severity
HIGH
CVSS
7.1
EPSS
0.18%

Original NVD Description

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.