CVE-2026-77773: Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry
The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed?
Sites using the Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before version 2.15.8 are affected where submitted entries exist for supported third-party forms.
Does exploitation require a WordPress account or a valid request token?
No. The affected public AJAX action lacks capability, nonce, and session checks, so unauthenticated users can invoke it.
What information can be disclosed?
An attacker can read submitted entries from forms created with a supported third-party form plugin through the formychat_get_gf_entry AJAX action.