---
id: CVE-2026-13359
title: >-
  The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
  plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
  cntctfrm_contact_dropdown Parameter in all versions up to, and including,
  1.7.5 due to i…
summary: >-
  The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
  plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
  cntctfrm_contact_dropdown Parameter in all versions up to, and including,
  1.7.5 due to i…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: bestweblayout
product: Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
affected:
  - >-
    contact_form_to_db_by_bestwebsoft_messages_database_plugin_for_wordpress <=
    1.7.5
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T17:17:15.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13359'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/contact-form-to-db/tags/1.7.4/contact_form_to_db.php#L2035
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/contact-form-to-db/tags/1.7.4/contact_form_to_db.php#L582
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3624996/contact-form-to-db'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/838dd2f9-22e3-4833-9f55-09bd729fd6ed?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-09T15:51:48.686694Z'
epss: 0.00236
epssPercentile: 0.1492
ingestedAt: '2026-09-09T02:57:45.160Z'
---

## Overview

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload executes in the context of an administrator's browser session when they visit the plugin's message manager page at /wp-admin/admin.php?page=cntctfrmtdb_manager, making it possible to compromise administrator-level sessions via a simple unauthenticated contact form submission.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
