What is CVE-2026-15735?
CVE-2026-15735 is a Stored Cross-Site Scripting (XSS) vulnerability in the 'Contact Form to Any API' plugin for WordPress, triggered via the 'cf7anyapi_form_field' Post Meta due to insufficient input sanitization and output escaping. It affects versions up to 3.0.6 and allows authenticated attackers (e.g., contributors) to inject malicious scripts. Updating the plugin is strongly recommended.
Azərbaycanca: CVE-2026-15735, WordPress-in "Contact Form to Any API" plaginində "cf7anyapi_form_field" Post Meta vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyidir. 3.0.6 və daha əvvəlki versiyalar təsirlənir; authenticated attacker (məsələn, contributor) zərərli skript yerləşdirə bilər. Plaginin son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15735?
CVE-2026-15735 affects the 'Contact Form to Any API' plugin for WordPress, specifically versions up to 3.0.6.
What level of access does an attacker need to exploit CVE-2026-15735?
To exploit this vulnerability, the attacker must be an authenticated user, such as one with contributor-level permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.