Skip to content
Threat Feed
high advisory

Stored XSS in Business Essentials for Contact Form 7

The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization in the gateway field.

CVE search metadata

CVE search record: CVE-2026-97661. Severity: high. CVSS: 7.2. KEV: no. Product: Business Essentials for Contact Form 7 (<= 1.2.1). Brief: Stored XSS in Business Essentials for Contact Form 7. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-97661/

The Business Essentials for Contact Form 7 plugin for WordPress (versions 1.2.1 and earlier) contains a critical security vulnerability identified as CVE-2026-97661. This vulnerability is a Stored Cross-Site Scripting (XSS) flaw located within the gateway form field. The vulnerability arises from insufficient input sanitization and output escaping when processing user-supplied data. Exploitation is possible when the plugin's Payments module is active and configured to support both PayPal and Stripe payment gateways. Unauthenticated attackers can exploit this by injecting malicious scripts into the form fields, which are subsequently stored and executed in the browsers of users viewing the affected pages. This flaw can lead to session hijacking, unauthorized actions, or redirection to malicious sites.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator or user session. This could result in the theft of authentication cookies, administrative credential harvesting, or further compromise of the WordPress environment. This vulnerability affects all installations using the specified plugin version range.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Identify all instances of the Business Essentials for Contact Form 7 plugin within the environment and confirm the version is 1.2.1 or below.
  • Disable the Payments module in the plugin settings as a temporary mitigation until an update is applied.
  • Implement a Content Security Policy (CSP) to restrict the execution of unauthorized scripts and mitigate the impact of potential XSS attacks.
  • Monitor web application logs for suspicious POST requests to forms utilizing the gateway parameter that contain HTML tags or JavaScript event handlers.

Immediate actions

Audit environment for Business Essentials for Contact Form 7 plugin installations and verify version.

Security Engineering 24h

Mitigations

Disable the Payments module in the Business Essentials for Contact Form 7 plugin until a patch is available.

immediate IT Operations

CVE-2026-97661