← WordPress Vulnerabilities
WordPress security by component

Contact Form by Supsystic

Contact Form by Supsystic is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Mar 30, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: contact-form-by-supsystic

CVE-2026-4257: Contact Form by Supsystic: Code execution

Contact Form by Supsystic is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 1.7.36.

PublishedMar 30, 2026
Known safe version> 1.7.36
Safe version
Mar 30, 2026 CVE-2026-4257
Contact Form by Supsystic: Code execution
Contact Form by Supsystic is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 1.7.36.
> 1.7.36
CVE9.8
NVDPending
Oct 22, 2025 CVE-2025-52753
Contact Form by Supsystic: Cross-site scripting
Contact Form by Supsystic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Apr 16, 2025 CVE-2024-13452
Contact Form by Supsystic: Cross-site request forgery
Contact Form by Supsystic is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.1
NVDPending
Oct 17, 2024 CVE-2024-48046
Contact Form by Supsystic: Cross-site scripting
Contact Form by Supsystic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Oct 16, 2024 CVE-2024-48042
Contact Form by Supsystic: Code execution
Contact Form by Supsystic is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.1
NVDPending
Oct 12, 2023 CVE-2023-45068
Contact Form By Supsystic: Cross-site request forgery
Contact Form By Supsystic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
May 17, 2023 CVE-2023-2528
Contact Form by Supsystic: Cross-site request forgery
Contact Form by Supsystic is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8