{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-13425/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-13425"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Database for CF7 plugin \u003c 1.2.7"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","xss","cve-2026-13425","stored-xss","plugin-vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA critical stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-13425, affects all versions up to and including 1.2.6 of the \u0026quot;Database for CF7\u0026quot; plugin for WordPress. This flaw stems from insufficient input sanitization and output escaping when handling array-structured input for ordinary text fields (e.g., \u003ccode\u003eyour-name[]\u003c/code\u003e). Unauthenticated attackers can exploit this by sending specially crafted HTTP POST requests containing malicious web scripts to the public REST API endpoint \u003ccode\u003e/wp-json/contact-form-7/v1/contact-forms/{id}/feedback\u003c/code\u003e. The plugin then stores this unsanitized input directly into its \u003ccode\u003ewp_cf7db\u003c/code\u003e database table, bypassing WordPress's default \u003ccode\u003ewp_insert_post\u003c/code\u003e and \u003ccode\u003ewp_kses\u003c/code\u003e filtering mechanisms. When a user, such as an administrator, subsequently views a page displaying the stored form data, the injected script executes in their browser context, leading to potential data theft, session hijacking, or website defacement.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker crafts an HTTP POST request containing malicious JavaScript within a form field.\u003c/li\u003e\n\u003cli\u003eThe attacker targets the \u003ccode\u003e/wp-json/contact-form-7/v1/contact-forms/{id}/feedback\u003c/code\u003e REST API endpoint of a vulnerable WordPress site.\u003c/li\u003e\n\u003cli\u003eThe malicious JavaScript is embedded within array-structured input parameters (e.g., \u003ccode\u003eyour-name[]=payload\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDue to insufficient input sanitization in the Database for CF7 plugin, this crafted input bypasses standard WordPress filtering.\u003c/li\u003e\n\u003cli\u003eThe plugin stores the unsanitized malicious payload directly into the \u003ccode\u003ewp_cf7db\u003c/code\u003e custom database table using \u003ccode\u003e$wpdb INSERT\u003c/code\u003e and \u003ccode\u003eserialize()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eA legitimate user (e.g., a site administrator) accesses a WordPress page that displays the submitted form data containing the stored payload.\u003c/li\u003e\n\u003cli\u003eThe browser renders the page, and the unsanitized malicious JavaScript retrieved from the database executes in the victim's browser context.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary web script execution, potentially leading to session hijacking, credential theft, or further client-side compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13425 allows unauthenticated attackers to execute arbitrary web scripts in the context of a victim's browser. This can lead to a range of severe consequences, including session hijacking, disclosure of sensitive information, defacement of web pages, or redirecting users to malicious sites. If an administrator account is compromised, attackers could gain full control over the affected WordPress site. While specific victim counts are not available for this newly disclosed vulnerability, the widespread use of WordPress and its plugins suggests a broad potential impact for organizations utilizing the Database for CF7 plugin in versions up to 1.2.6.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Database for CF7 plugin for WordPress to version 1.2.7 or higher to patch CVE-2026-13425.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-13425 Exploitation Attempt - WordPress CF7 XSS\u0026quot; to your SIEM to identify attempts to inject malicious array-structured input via the \u003ccode\u003e/wp-json/contact-form-7/v1/contact-forms/{id}/feedback\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eBlock the URL \u003ccode\u003e/wp-json/contact-form-7/v1/contact-forms/{id}/feedback\u003c/code\u003e at the web application firewall (WAF) or web server level if immediate patching is not possible, ensuring the URL includes the wildcard \u003ccode\u003e{id}\u003c/code\u003e for the contact form ID.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for requests containing the IOC \u003ccode\u003e/wp-json/contact-form-7/v1/contact-forms/{id}/feedback\u003c/code\u003e combined with \u003ccode\u003e[]\u003c/code\u003e in the query string and suspicious characters, as described in the Sigma rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T09:20:00Z","date_published":"2026-07-29T09:20:00Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-cf7-xss/","summary":"The Database for CF7 plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via Array Form Field Values, allowing unauthenticated attackers to inject arbitrary web scripts by sending specially crafted array-structured input to the Contact Form 7 REST API endpoint /wp-json/contact-form-7/v1/contact-forms/{id}/feedback, which are insufficiently sanitized and executed when a user accesses an affected page.","title":"WordPress Database for CF7 Plugin Stored Cross-Site Scripting (CVE-2026-13425)","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-cf7-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-13425","version":"https://jsonfeed.org/version/1.1"}