CVE-2026-12801: Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12801?
CVE-2026-12801 has a severity rating of medium, with a score of 6.4.
How do I fix CVE-2026-12801?
To fix CVE-2026-12801, update the Ultra Addons for Contact Form 7 plugin to a version beyond 3.5.43.
What type of vulnerability is CVE-2026-12801?
CVE-2026-12801 is a Stored Cross-Site Scripting (XSS) vulnerability.
What components are affected by CVE-2026-12801?
CVE-2026-12801 affects the Range Slider 'data-label' and 'data-separator' attributes in the Ultra Addons for Contact Form 7 plugin.
Who is affected by CVE-2026-12801?
Users with the Ultra Addons for Contact Form 7 plugin installed, particularly those with Contributor+ roles, are at risk due to this vulnerability.