๐Ÿ” CVE Alert

CVE-2022-50959

MEDIUM 6.1

WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php

CVSS Score
6.1
EPSS Score
0.1%
EPSS Percentile
24th

WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.

CWE CWE-79
Vendor wpdevart
Product contact form builder
Published May 10, 2026
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for wpdevart contact form builder

Be the first to know when new medium vulnerabilities affecting wpdevart contact form builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

wpdevart / Contact Form Builder
1.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/50734 wordpress.org: https://wordpress.org/plugins/contact-forms-builder/ vulncheck.com: https://www.vulncheck.com/advisories/wordpress-contact-form-builder-cross-site-scripting-via-code-generator-php

Credits

Milad karimi