Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-83625— Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header

Quick assessment

Affected
supsysticcom Contact Form by Supsystic
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 "The Contact Form by Supsystic" 插件存在存储型跨站脚本攻击(Stored XSS)漏洞。 漏洞描述: 该插件在 1.10.2 及之前所有版本中,由于对输入数据缺乏足够的过滤和输出时未进行转义,使得未认证的远程攻击者能够向页面的 IP 地址请求头(如 )中注入恶意脚本。当用户访问被注入的页面时,这些脚本将会被执行。 攻击流程: 1. 未认证的 attacker 可以先调用 操作——由于该操作未包含在插件的权限列表中,因此无需身份验证即可访问——以获取一个有效的

CVSS 7.2 · High

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-83625

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header
Source: CVE Program / CVE List V5
Vulnerability Description
The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence from the plugin's permission list — to obtain a valid nonce, then submit a contact form with a malicious payload in a spoofed IP header such as X-Forwarded-For.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
supsysticcom Contact Form by Supsystic 0 ~ 1.10.2 -

II. Public POCs for CVE-2026-83625

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-83625

登录查看更多情报信息。

Patches & Fixes for CVE-2026-83625 (2)

Vendor Advisories for CVE-2026-83625 (1)

Vendor Pages for CVE-2026-83625 (2)

Other References for CVE-2026-83625 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-83625

No comments yet


Leave a comment