9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
⚡ WordPress - Contact Form 7 - Unauthenticated SSTI To Remote Command Execution CVE-2026-4257 is a critical Server-Side Template Injection SSTI vulnerability in Contact Form 7 versions up to 1.7.36, allowing unauthenticated remote attackers to execute...
Basic Information
ID
12BCB450-9365-5457-BD3E-61E9AFB1F9B5
Published
Apr 18, 2026 at 19:39
Modified
Apr 18, 2026 at 19:44