S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 31, 2026

CVE-2026-4257 Scanner

CVE-2026-4257 Scanner - Server Side Template Injection (SSTI) vulnerability in WordPress Contact Form by Supsystic

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-4257
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated attackers to execute arbitrary PHP functions and OS commands on the server by leveraging Twig's `registerUndefinedFilterCallback()` method to register arbitrary PHP callbacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Contact Form by Supsysticby supsysticcom
0
Updated Sep 10, 2026View on NVD →
Detail

WordPress Contact Form by Supsystic is a popular plugin used by website administrators to add contact form functionalities to their WordPress sites. It provides a wide range of customizable features, making it easy for users to create forms for contact, feedback, or other purposes. This plugin is widely adopted, especially by businesses and bloggers who seek a user-friendly way to implement contact forms. However, the plugin can be vulnerable to security issues if not updated regularly. Users rely on it to enhance the communication interface of their website, making security essential. Hence, maintaining updated versions is crucial for website safety.

The server-side template injection vulnerability allows a remote attacker to execute arbitrary code on the server. This issue arises when unsandboxed code is processed, allowing for execution of harmful code through user-supplied input. In the case of WordPress Contact Form by Supsystic, this vulnerability affects versions <= 1.7.36. Unauthenticated attackers can exploit this feature via specific GET parameters. Such vulnerabilities can compromise the integrity and security of a server, leading to unauthorized access.

Technical details reveal that this vulnerability involves the use of unsandboxed `Twig_Loader_String` and `cfsPreFill` functionality. The vulnerable parameter is manipulated via GET requests that allow for remote code execution. This exploitation can occur without authentication, increasing the ease with which an attacker can gain control. The GET parameters are manipulated to inject and execute malicious code, posing a significant security risk. The critical nature of this vulnerability requires immediate attention and patching.

If an attacker exploits this vulnerability, it could lead to complete server compromise. The attacker may execute arbitrary PHP functions and operating system commands remotely. Consequently, sensitive data could be exposed, modified, or destroyed. Furthermore, server operations could be disrupted, affecting website availability and integrity. This vulnerability provides a foothold for further attacks, including installing backdoors or malware. Organizations could suffer reputational damage and financial loss from any service disruption or data breach.

REFERENCES

Solution Advice
  • Update the WordPress Contact Form by Supsystic plugin to the latest version beyond 1.7.36.
  • Regularly monitor and update all plugins and themes to their latest versions to prevent known vulnerabilities.
  • Consider implementing a web application firewall (WAF) to mitigate potential injection attacks.
  • Follow security best practices for WordPress sites including regular backups and using secure authentication methods.
  • Conduct periodic security audits to identify and address potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.