{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asupsysticcontact_formwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:supsystic:contact_form:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-83625"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Contact Form by Supsystic (\u003c= 1.10.2)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Supsystic"],"content_html":"\u003cp\u003eThe Contact Form by Supsystic plugin for WordPress (versions 1.10.2 and earlier) contains a critical security flaw allowing for Stored Cross-Site Scripting (XSS). An unauthenticated attacker can exploit this vulnerability by manipulating HTTP headers, specifically the 'X-Forwarded-For' header, during the contact form submission process. Because the plugin fails to properly sanitize this input before storing and rendering it, injected JavaScript is executed within the browser of any user - including administrators - who views the malicious data in the WordPress dashboard or public-facing pages.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is compounded by a secondary issue involving the 'updateNonce' action, which lacks proper authentication checks. Attackers can leverage this to acquire a valid nonce, subsequently bypassing form protections to finalize the submission of the malicious XSS payload. Successful exploitation allows for account takeover, unauthorized administrative actions, or credential theft, depending on the privileges of the victim viewing the injected content.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP GET/POST request to the target site to trigger the 'updateNonce' action.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin returns a valid nonce due to the absence of authentication checks on the 'updateNonce' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request containing a scripted payload (e.g., \u003ccode\u003e\u0026lt;script\u0026gt;alert(1)\u0026lt;/script\u0026gt;\u003c/code\u003e) inside the 'X-Forwarded-For' header.\u003c/li\u003e\n\u003cli\u003eThe request is submitted to the plugin's contact form endpoint, including the previously obtained nonce.\u003c/li\u003e\n\u003cli\u003eThe plugin saves the form data, including the malicious script from the header, into the WordPress database without sanitization.\u003c/li\u003e\n\u003cli\u003eA victim (likely an administrator) accesses the WordPress dashboard or a page displaying the form submissions.\u003c/li\u003e\n\u003cli\u003eThe browser renders the stored payload, executing the JavaScript in the context of the victim's session.\u003c/li\u003e\n\u003cli\u003eThe script performs unauthorized actions or exfiltrates session data to the attacker-controlled endpoint.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables unauthenticated attackers to execute arbitrary JavaScript in the browsers of users viewing the injected content. This poses a high risk to WordPress site administrators, as it can lead to full site compromise, unauthorized configuration changes, or the theft of administrative session cookies.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Contact Form by Supsystic plugin to a version patched against CVE-2026-83625 immediately.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect and sanitize 'X-Forwarded-For' headers for script tags and malicious characters.\u003c/li\u003e\n\u003cli\u003eAudit WordPress administrative logs for suspicious requests to the 'updateNonce' action.\u003c/li\u003e\n\u003cli\u003eReview all stored contact form submissions for signs of anomalous script injection if administrative access was potentially compromised.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T09:31:01Z","date_published":"2026-09-05T09:31:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-83625/","summary":"The Contact Form by Supsystic WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting due to insufficient sanitization of X-Forwarded-For headers.","title":"Stored XSS in Contact Form by Supsystic","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-83625/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:supsystic:contact_form:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}