WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
Metrics
Affected Vendors & Products
References
History
Sun, 10 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpdevart Wpdevart contact Form Builder |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpdevart Wpdevart contact Form Builder |
Sun, 10 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers. | |
| Title | WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-10T12:12:53.644Z
Reserved: 2026-01-11T13:34:26.332Z
Link: CVE-2022-50959
No data.
Status : Received
Published: 2026-05-10T13:16:33.570
Modified: 2026-05-10T13:16:33.570
Link: CVE-2022-50959
No data.
OpenCVE Enrichment
Updated: 2026-05-10T13:30:12Z