Official Product Homepageproduct
https://form2email.dwbooster.com/ CVE-2021-47926
MEDIUM
WordPress Contact Form to Email 1.3.24 Stored XSS
Record summary
CVE-2021-47926 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Contact Form to EmailBrowse Form2Email / Contact Form to Email | CVE List | 1.3.24 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Contact Form to Email 1.3.24 - Stored Cross Site Scripting (XSS) (Authenticated)ExploitDB exploitby Mohammed Aadhil AshfaqNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47926 ExploitDB-50524exploit
https://www.exploit-db.com/exploits/50524 VulnCheck Advisory: WordPress Contact Form to Email 1.3.24 Stored XSSThird-party advisory
https://www.vulncheck.com/advisories/wordpress-contact-form-to-email-stored-xss