CVE-2026-100513: WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CF7 Views – Complete Entry Management for Contact Form 7to a version that resolves this vulnerability.Fixed in 3.2.6
Event History
Frequently Asked Questions
Who could exploit this issue?
An attacker needs Contributor-level access to a WordPress site using the affected plugin. Exploitation also requires user interaction.
Which plugin versions are affected?
CF7 Views – Complete Entry Management for Contact Form 7 versions 3.2.5 and earlier are affected.
What impact can successful exploitation have?
The issue is a cross-site scripting vulnerability with low confidentiality, integrity, and availability impact. Its scope is changed, meaning the impact can extend beyond the vulnerable component's security authority.