CVE-2026-18946

7.5

WordPress · Contact Form to Any API

The Contact Form to Any API plugin for WordPress is vulnerable to information exposure, potentially allowing unauthenticated attackers to access sensitive data.

Executive summary

An unauthenticated information exposure vulnerability in the Contact Form to Any API WordPress plugin poses a significant risk of unauthorized data access.

Vulnerability

This vulnerability involves information exposure (CWE-200) that is accessible to unauthenticated attackers. The flaw allows remote users to access data that should otherwise be protected or restricted.

Business impact

The exploitation of this vulnerability could lead to the exposure of sensitive user or configuration data, resulting in privacy breaches or providing attackers with information to facilitate further attacks. With a CVSS score of 7.5, the vulnerability is classified as high severity, reflecting the ease of exploitation and the potential for unauthorized data disclosure.

Remediation

Immediate Action: Update the Contact Form to Any API plugin to version 3.0.7 or later immediately.

Proactive Monitoring: Monitor site traffic and application logs for suspicious access patterns targeting plugin-related endpoints or unexpected data retrieval requests.

Compensating Controls: Implement a Web Application Firewall to block common exploitation patterns targeting WordPress plugins until the update is deployed.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the availability of a proof-of-concept and the high severity of this information exposure, users should update the plugin immediately. If an update cannot be applied, consider deactivating the plugin to prevent potential data compromise.

More WordPress CVEs