CVE-2026-73379: WordPress Contact Form by Supsystic plugin < 1.10.0 - Bypass Vulnerability vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Affected Software
1 affected component
Supsystic WordPress Contact Form<1.10.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Contact Form by Supsystic Pluginto a version that resolves this vulnerability.Fixed in 1.10.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites running Contact Form by Supsystic versions earlier than 1.10.0 are affected. The issue is reachable over the network without authentication or user interaction.
2
What does an attacker need to exploit this issue?
An attacker does not need an account, elevated privileges, or victim interaction. The published vector indicates low attack complexity and network-based exploitation.
3
What should administrators do to remediate the issue?
Update Contact Form by Supsystic to version 1.10.0 or later. The provided information does not identify a workaround for sites that cannot update immediately.