Skip to content

Known CVE

WordPress Contact Form by Supsystic - Server-Side Template Injection

Contact Form by Supsystic WordPress plugin <= 1.7.36 contains a server-side template injection caused by unsandboxed Twig_Loader_String and cfsPreFill functionality, letting unauthenticated attackers execute arbitrary code remotely via GET parameters.

CVE-2026-4257

Critical2026CVSS 9.8CWE-94

cve2026 · wordpress · wp-plugin · contact-form-by-supsystic · ssti · rce · twig · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website