<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Contact Form to DB by BestWebSoft – Messages Database Plugin for WordPress (&lt;= 1.7.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/contact-form-to-db-by-bestwebsoft--messages-database-plugin-for-wordpress--1.7.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 03:51:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/contact-form-to-db-by-bestwebsoft--messages-database-plugin-for-wordpress--1.7.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in BestWebSoft Contact Form to DB Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-xss-bestwebsoft/</link><pubDate>Wed, 09 Sep 2026 03:51:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-xss-bestwebsoft/</guid><description>The Contact Form to DB WordPress plugin (&lt;= 1.7.5) is vulnerable to unauthenticated Stored Cross-Site Scripting via the cntctfrm_contact_dropdown parameter, allowing attackers to execute scripts in an administrator's browser session.</description><content:encoded><![CDATA[<p>The 'Contact Form to DB by BestWebSoft - Messages Database Plugin' for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-13359. The vulnerability exists in all versions up to and including 1.7.5. It stems from insufficient input sanitization and output escaping on the 'cntctfrm_contact_dropdown' parameter.</p>
<p>An unauthenticated attacker can submit a crafted payload through the plugin's contact form. This payload is stored in the database and subsequently executed when an administrator views the submission within the plugin's message manager interface (/wp-admin/admin.php?page=cntctfrmtdb_manager). Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the administrator's session, potentially leading to unauthorized administrative actions, session hijacking, or site redirection.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation compromises the integrity and confidentiality of the WordPress administrative session. By executing scripts in the administrator's browser, an attacker could create new administrative accounts, modify site content, or perform other unauthorized actions. This vulnerability affects all WordPress instances using the specified plugin version.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the 'Contact Form to DB by BestWebSoft' plugin to the latest version immediately.</li>
<li>Until patched, disable the affected plugin if it is not business-critical.</li>
<li>Implement a Web Application Firewall (WAF) to inspect and block incoming HTTP requests containing suspicious script tags or JavaScript event handlers in the 'cntctfrm_contact_dropdown' parameter.</li>
<li>Monitor web server access logs for anomalous POST requests to the contact form endpoint that contain HTML/JavaScript syntax.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-13359</category></item></channel></rss>