What is CVE-2026-65438?
CVE-2026-65438 is an Unauthenticated Cross Site Scripting (XSS) vulnerability discovered in the 'Message Filter for Contact Form 7' plugin. It affects versions up to 1.6.3.9 and could allow an attacker to hijack user sessions. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-65438, Contact Form 7 üçün 'Message Filter' plaginində aşkarlanmış autentifikasiya tələb etməyən Cross Site Scripting (XSS) zəifliyidir. Bu boşluq 1.6.3.9 və daha əvvəlki versiyalara təsir edir və təcavüzkara istifadəçi sessiyalarını ələ keçirməyə imkan verə bilər. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin and versions are affected by CVE-2026-65438?
CVE-2026-65438 affects the 'Message Filter for Contact Form 7' plugin. The vulnerability exists in versions up to 1.6.3.9.
What can an attacker achieve by exploiting this vulnerability?
Since CVE-2026-65438 is an Unauthenticated XSS vulnerability, an attacker could hijack user sessions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.