CVE-2026-8172

HIGH

Simple Basic Contact Form <= 20250114 - Reflected XSS

Title source: cna
STIX 2.1

Description

The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/535ec1a1-b822-43c9-8264-6442199493d3/

Scores

CVSS v3 7.1
EPSS 0.0016
EPSS Percentile 5.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (1)
None/Simple Basic Contact Form < 20250114
Published Jun 23, 2026
Tracked Since Jun 23, 2026