What is CVE-2026-12801?
This CVE describes a Stored Cross-Site Scripting (XSS) vulnerability in the 'Ultra Addons for Contact Form 7' WordPress plugin up to version 3.5.43, caused by insufficient input sanitization. Attackers can inject malicious scripts via the Range Slider's 'data-label' and 'data-separator' attributes, potentially leading to data theft. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu CVE, WordPress-in 'Ultra Addons for Contact Form 7' plaginində (3.5.43-ə qədər versiyalarda) saxlanılmış Stored Cross-Site Scripting (XSS) zəifliyini təsvir edir. Təcavüzkar Range Slider komponentindəki 'data-label' və 'data-separator' atributları vasitəsilə zərərli skript yerləşdirə bilər ki, bu da istifadəçi məlumatlarının oğurlanmasına səbəb ola bilər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WordPress plugin are affected by CVE-2026-12801?
Versions of the Ultra Addons for Contact Form 7 plugin up to 3.5.43 are affected by this Stored XSS vulnerability.
How can an attacker inject a malicious script in the CVE-2026-12801 vulnerability?
An attacker can inject malicious scripts via the Range Slider component's 'data-label' and 'data-separator' attributes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.