What is CVE-2026-10734?
CVE-2026-10734 is a Stored Cross-Site Scripting (XSS) vulnerability in the Infility Global plugin for WordPress. It allows unauthenticated attackers to inject arbitrary web scripts via the /cf7_record log endpoint due to insufficient input sanitization and output escaping. Sites using this plugin should update to the latest version immediately.
Azərbaycanca: CVE-2026-10734, WordPress üçün Infility Global plaginində Stored Cross-Site Scripting (XSS) zəifliyidir. /cf7_record log endpoint-i vasitəsilə autentifikasiya olunmamış hücumçulara veb skriptləri inyeksiya etməyə imkan verir. Plagindən istifadə edən saytlar dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can an attacker inject malicious scripts using the CVE-2026-10734 vulnerability?
An unauthenticated attacker can inject arbitrary web scripts via the /cf7_record log endpoint through Stored Cross-Site Scripting (XSS).
What should a site owner do to protect against CVE-2026-10734?
Sites using the Infility Global plugin for WordPress should update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.