CVE-2026-32460

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.5.36.
Configurations

No configuration.

History

16 Mar 2026, 14:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting') en Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Ultimate Addons for Contact Form 7: desde n/a hasta &lt;= 3.5.36.

13 Mar 2026, 19:55

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:55

Updated : 2026-03-16 14:19


NVD link : CVE-2026-32460

Mitre link : CVE-2026-32460

CVE.ORG link : CVE-2026-32460


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')