Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96752— Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration

Quick assessment

Affected
bmarshall511 Zero Spam for WordPress
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Zero Spam 插件在 5.7.10 及更早版本中,由于输入数据未充分净化且输出未正确转义,存在通过 Contact Form 7 集成中的嵌套 POST 数组键实现存储型跨站脚本攻击(Stored XSS)的漏洞。 该漏洞允许未认证的 attackers 向页面注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将被执行。攻击载荷通过提交一个包含任意 HTML 或 JavaScript 的嵌套 POST 数组键的 Contact Form 7 请求来投递。PHP 会将该字段名解析

CVSS 7.2 · High EPSS 0.24% · P14

Affected Version Matrix 1

VendorProduct Version RangeStatus
bmarshall511 Zero Spam for WordPress ≤ 5.7.10 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96752

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration
Source: CVE Program / CVE List V5
Vulnerability Description
The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in all versions up to, and including, 5.7.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered by submitting a Contact Form 7 request with a nested POST array key containing arbitrary HTML or JavaScript — PHP parses the field name into a nested array key, which is stored verbatim in the zerospam_log.submission_data column when Zero Spam flags the submission as spam due to the absence of the zerospam_david_walsh_key field.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bmarshall511 Zero Spam for WordPress 0 ~ 5.7.10 -

II. Public POCs for CVE-2026-96752

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96752

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-96752 (2)

Vendor Advisories for CVE-2026-96752 (1)

Vendor Pages for CVE-2026-96752 (1)

Other References for CVE-2026-96752 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-96752

No comments yet


Leave a comment