Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itpathsolutions
Itpathsolutions contact Form To Any Api Wordpress Wordpress wordpress |
|
| Vendors & Products |
Itpathsolutions
Itpathsolutions contact Form To Any Api Wordpress Wordpress wordpress |
Mon, 15 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions. | |
| Title | WordPress Contact Form to Any API plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-16T17:42:09.522Z
Reserved: 2026-04-07T08:24:32.861Z
Link: CVE-2026-39449
Updated: 2026-06-16T17:41:58.698Z
Status : Deferred
Published: 2026-06-15T21:16:43.000
Modified: 2026-06-15T21:24:32.790
Link: CVE-2026-39449
No data.
OpenCVE Enrichment
Updated: 2026-06-18T01:15:15Z