CVE-2026-18946
7.5WordPress · Contact Form to Any API
The Contact Form to Any API plugin for WordPress is vulnerable to information exposure, potentially allowing unauthenticated attackers to access sensitive data.
Executive summary
An unauthenticated information exposure vulnerability in the Contact Form to Any API WordPress plugin poses a significant risk of unauthorized data access.
Vulnerability
This vulnerability involves information exposure (CWE-200) that is accessible to unauthenticated attackers. The flaw allows remote users to access data that should otherwise be protected or restricted.
Business impact
The exploitation of this vulnerability could lead to the exposure of sensitive user or configuration data, resulting in privacy breaches or providing attackers with information to facilitate further attacks. With a CVSS score of 7.5, the vulnerability is classified as high severity, reflecting the ease of exploitation and the potential for unauthorized data disclosure.
Remediation
Immediate Action: Update the Contact Form to Any API plugin to version 3.0.7 or later immediately.
Proactive Monitoring: Monitor site traffic and application logs for suspicious access patterns targeting plugin-related endpoints or unexpected data retrieval requests.
Compensating Controls: Implement a Web Application Firewall to block common exploitation patterns targeting WordPress plugins until the update is deployed.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the availability of a proof-of-concept and the high severity of this information exposure, users should update the plugin immediately. If an update cannot be applied, consider deactivating the plugin to prevent potential data compromise.