cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsocial-contact-form social-contact-form

Direction: ascending
Jul 11, 2026

Connect Form to Chat Apps with Contact Form 7 Integration – FormyChat # CVE-2026-57379

CVE, Research URL

CVE-2026-57379

Date
Jul 13, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.
Affected versions
max 2.15.4.
Status
vulnerable
Aug 20, 2026

Connect Form to Chat Apps with Contact Form 7 Integration &#8211; FormyChat # CVE-2026-28571

CVE, Research URL

CVE-2026-28571

Date
Aug 18, 2026
Research Description
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
Affected versions
max 2.15.7.
Status
vulnerable
Sep 15, 2026

Connect Form to Chat Apps with Contact Form 7 Integration &#8211; FormyChat # CVE-2026-77773

CVE, Research URL

CVE-2026-77773

Date
Sep 13, 2026
Research Description
The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.
Affected versions
max 2.15.8.
Status
vulnerable