CVE-2026-81300: WordPress Calculation For Contact Form 7 plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Calculation For Contact Form 7 pluginto a version that resolves this vulnerability.Fixed in 1.1
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation does require user interaction, as indicated by the UI:R vector.
Which installations are affected?
Calculation For Contact Form 7 versions 1.0 and earlier are affected. The provided data does not identify a fixed version or configuration-specific prerequisites.
What impact can successful exploitation have?
Successful XSS can affect confidentiality, integrity, and availability at low impact levels. The scope is changed, meaning the impact can extend beyond the vulnerable plugin's security authority.