PT-2026-39484 · WordPress · Contact Form Builder

Milad Karimi

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2022-50959

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Contact Form Builder version 1.6.1
Description A reflected cross-site scripting issue allows unauthenticated attackers to inject malicious scripts. This is achieved by sending crafted URLs to the 'code generator.php' endpoint using the form id parameter, which enables the execution of arbitrary JavaScript in the victim's browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-50959

Affected Products

Contact Form Builder