PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 31, 2026

WordPress Contact Form by Supsystic - Server-Side Template Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-4257
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated attackers to execute arbitrary PHP functions and OS commands on the server by leveraging Twig's `registerUndefinedFilterCallback()` method to register arbitrary PHP callbacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Contact Form by Supsysticby supsysticcom
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WordPress Contact Form by Supsystic - Server-Side Template Injection CVE-2026-4257 Scanner | S4E