Skip to content
Threat Feed
high advisory

Stored XSS in Magic Tooltips For Contact Form 7 Plugin

An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Magic Tooltips For Contact Form 7 plugin up to version 1.0.34 allows attackers to inject malicious scripts via the author parameter.

CVE search metadata

CVE search record: CVE-2026-101928. Severity: high. CVSS: 7.2. KEV: no. Product: Magic Tooltips For Contact Form 7 (<= 1.0.34). Brief: Stored XSS in Magic Tooltips For Contact Form 7 Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-xss-magic-tooltips/

The Magic Tooltips For Contact Form 7 plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-101928) impacting all versions up to and including 1.0.34. The flaw stems from insufficient input sanitization and improper output escaping within the plugin's comment handling logic. Specifically, the plugin employs an 'esc_html' filter callback that inadvertently decodes HTML-entity-encoded payloads back into live HTML.

An unauthenticated attacker can supply a malicious script payload, encoded as HTML entities, within the 'author' parameter of a comment submission. This payload bypasses the standard 'sanitize_text_field' protections. Once stored, the script executes in the context of an administrator's browser when they access the 'wp-admin/edit-comments.php' page. This represents a significant risk for privilege escalation via session hijacking or administrative action manipulation within the WordPress dashboard.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This may lead to account takeover, unauthorized administrative actions, or the deployment of further malicious content within the site, potentially compromising all users and data managed by the affected WordPress instance.

Recommendation

  • Update the Magic Tooltips For Contact Form 7 plugin to a version later than 1.0.34, or disable the plugin until a patch is applied.
  • Monitor web server access logs for POST requests to comment submission endpoints containing HTML entity-encoded patterns or suspicious script tags.
  • Implement a Web Application Firewall (WAF) rule to block POST requests containing common XSS vectors in comment form parameters.

Immediate actions

Update Magic Tooltips For Contact Form 7 to latest available version

IT Operations 24h

Mitigations

Disable plugin if update is unavailable

immediate IT Operations

CVE-2026-101928