Contact Form to Any API
Contact Form to Any API is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 29, 2026; the highest CVE/CNA score is 8.5.
contact-form-to-any-apiCVE-2026-15735: Contact Form to Any API mapping metadata permits contributor stored XSS
Contact Form to Any API through 3.0.6 lets an authenticated Contributor store an attribute-breakout payload in the cf7anyapi_form_field post meta of a cf7_to_any_api configuration. When its mapping fields are loaded, the logged-in admin AJAX action cf7_to_any_api_get_form_field accepts form_id and post_id, reads that metadata, and concatenates each stored value directly into an HTML input value attribute without output escaping. Inserting the returned form-field HTML into the settings interface can therefore execute the stored script in a user's browser. The authoritative record does not disclose a more specific victim-navigation sequence.
| Safe version |
|
||
|---|---|---|---|
| Jul 29, 2026 |
CVE-2026-15735
Contact Form to Any API mapping metadata permits contributor stored XSS
Contact Form to Any API through 3.0.6 lets an authenticated Contributor store an attribute-breakout payload in the cf7anyapi_form_field post meta of a cf7_to_any_api configuration. When its mapping fields are loaded, the logged-in admin AJAX action cf7_to_any_api_get_form_field accepts form_id and post_id, reads that metadata, and concatenates each stored value directly into an HTML input value attribute without output escaping. Inserting the returned form-field HTML into the settings interface can therefore execute the stored script in a user's browser. The authoritative record does not disclose a more specific victim-navigation sequence.
|
3.0.7 |
CVE6.4
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39449
Contact Form to Any API: Cross-site scripting
Contact Form to Any API is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.0.3.
|
> 3.0.3 |
CVE7.1
NVDPending
|
| Dec 09, 2024 |
CVE-2023-47871
Contact Form to Any API: A security weakness
Contact Form to Any API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 25, 2024 |
CVE-2024-7617
Contact Form to Any API: Cross-site scripting
Contact Form to Any API is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Mar 28, 2024 |
CVE-2024-30242
Contact Form to Any API: SQL injection
Contact Form to Any API is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Nov 04, 2023 |
CVE-2023-32741
Contact Form to Any API: SQL injection
Contact Form to Any API is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|