{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-13359/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bestwebsoft:contact_form_to_db_by_bestwebsoft_messages_database_plugin_for_wordpress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-13359"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress (\u003c= 1.7.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-13359"],"_cs_type":"advisory","_cs_vendors":["BestWebSoft"],"content_html":"\u003cp\u003eThe 'Contact Form to DB by BestWebSoft - Messages Database Plugin' for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-13359. The vulnerability exists in all versions up to and including 1.7.5. It stems from insufficient input sanitization and output escaping on the 'cntctfrm_contact_dropdown' parameter.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can submit a crafted payload through the plugin's contact form. This payload is stored in the database and subsequently executed when an administrator views the submission within the plugin's message manager interface (/wp-admin/admin.php?page=cntctfrmtdb_manager). Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the administrator's session, potentially leading to unauthorized administrative actions, session hijacking, or site redirection.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation compromises the integrity and confidentiality of the WordPress administrative session. By executing scripts in the administrator's browser, an attacker could create new administrative accounts, modify site content, or perform other unauthorized actions. This vulnerability affects all WordPress instances using the specified plugin version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Contact Form to DB by BestWebSoft' plugin to the latest version immediately.\u003c/li\u003e\n\u003cli\u003eUntil patched, disable the affected plugin if it is not business-critical.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to inspect and block incoming HTTP requests containing suspicious script tags or JavaScript event handlers in the 'cntctfrm_contact_dropdown' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to the contact form endpoint that contain HTML/JavaScript syntax.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T03:51:30Z","date_published":"2026-09-09T03:51:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-xss-bestwebsoft/","summary":"The Contact Form to DB WordPress plugin (\u003c= 1.7.5) is vulnerable to unauthenticated Stored Cross-Site Scripting via the cntctfrm_contact_dropdown parameter, allowing attackers to execute scripts in an administrator's browser session.","title":"Stored XSS in BestWebSoft Contact Form to DB Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-xss-bestwebsoft/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-13359","version":"https://jsonfeed.org/version/1.1"}