SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-77773

MEDIUM · CVSS 5.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin versions prior to 2.15.8 are vulnerable due to a lack of capability, nonce, or session checks on a public AJAX action, enabling unauthenticated users to access submitted form entries. This exposure can lead to unauthorized data disclosure, potentially compromising sensitive user information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-77773
Severity
MEDIUM
CVSS
5.3
EPSS
N/A
WordPress

Original NVD Description

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.