WordPress security by component
Contact Form to Any API
Plugin description
Contact Form to Any API is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Aug 10, 2026; the highest published CVSS base score is 8.5.
Plugin slug:
contact-form-to-any-apiLatest vulnerability
CVE-2026-18946: Contact Form to Any API exposes predictable uploaded files
Contact Form to Any API before 3.0.7 copies files submitted through contact forms into a publicly accessible directory without assigning random filenames. An unauthenticated attacker can enumerate predictable filenames and download files submitted by other users. The CNA does not disclose the contact-form integration, upload field, public directory, filename derivation, or enumeration request format.
| Safe version |
|
||
|---|---|---|---|
| Aug 10, 2026 |
CVE-2026-18946
Contact Form to Any API exposes predictable uploaded files
Contact Form to Any API before 3.0.7 copies files submitted through contact forms into a publicly accessible directory without assigning random filenames. An unauthenticated attacker can enumerate predictable filenames and download files submitted by other users. The CNA does not disclose the contact-form integration, upload field, public directory, filename derivation, or enumeration request format.
|
3.0.7 |
CVE7.5
NVDPending
|
| Jul 29, 2026 |
CVE-2026-15735
Contact Form to Any API mapping metadata permits contributor stored XSS
Contact Form to Any API through 3.0.6 lets an authenticated Contributor store an attribute-breakout payload in the cf7anyapi_form_field post meta of a cf7_to_any_api configuration. When its mapping fields are loaded, the logged-in admin AJAX action cf7_to_any_api_get_form_field accepts form_id and post_id, reads that metadata, and concatenates each stored value directly into an HTML input value attribute without output escaping. Inserting the returned form-field HTML into the settings interface can therefore execute the stored script in a user's browser. The authoritative record does not disclose a more specific victim-navigation sequence.
|
3.0.7 |
CVE6.4
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39449
Contact Form to Any API: Cross-site scripting
Contact Form to Any API is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.0.3.
|
> 3.0.3 |
CVE7.1
NVDPending
|
| Dec 09, 2024 |
CVE-2023-47871
Contact Form to Any API: A security weakness
Contact Form to Any API is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 25, 2024 |
CVE-2024-7617
Contact Form to Any API: Cross-site scripting
Contact Form to Any API is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Mar 28, 2024 |
CVE-2024-30242
Contact Form to Any API: SQL injection
Contact Form to Any API is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Nov 04, 2023 |
CVE-2023-32741
Contact Form to Any API: SQL injection
Contact Form to Any API is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|