CVE-2026-57411: WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57411?
CVE-2026-57411 has a high severity rating of 7.1.
How do I fix CVE-2026-57411?
To fix CVE-2026-57411, update the WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin to version 3.2.3 or later.
What type of vulnerability is CVE-2026-57411?
CVE-2026-57411 is a Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-57411?
CVE-2026-57411 affects users of the CF7 Views – Complete Entry Management for Contact Form 7 plugin versions 3.2.2 and earlier.
What is the potential impact of CVE-2026-57411?
The potential impact of CVE-2026-57411 includes unauthorized script execution in users' browsers, which can lead to data theft and other malicious activities.