Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
Vulnerabilities

CVE-2026-83625: Security vulnerability

CVE-2026-83625: The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and inclu. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NIST NVDSep 7, 2026, 12:17 PM UTCCVE-2026-83625
THE STORY

What happened

22 story lines • source-grounded narrative

CVE-2026-83625: The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and inclu. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call.

The issue currently carries a HIGH 7 2 severity signal in the CyberDeltaForce record. The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls. If you use the affected technology, first check whether the vulnerable component is actually present and reachable.

The current severity assessment is HIGH 7 2. Real risk depends on exposure, exploitability, compensating controls and the importance of the affected asset—not the CVSS number alone. Security outcome — Not publicly disclosed in enough detail to state a specific post-exploitation result without inference.

The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries. 2 due to insufficient input sanitization and output escaping.

Confirmed Initial trigger — attacker-controlled network input reaches the vulnerable function on the affected The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all service. The issue is tracked as CVE-2026-83625. The current record lists the severity as HIGH 7.2.

The current record does not mark the vulnerability as actively exploited. NIST NVD published the primary report used for this article on Sep 7, 2026. The available advisory information identifies up to, and inclu The Contact Form by Supsystic plugin for WordPress as affected versions.

Confirmed Exploit mechanism — the reported cross-site scripting is triggered inside The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all, crossing the security boundary described by the advisory or vulnerability record. Inventory affected products and versions. Validate external and internal reachability of the vulnerable function.

Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.

CDF ANALYSIS

Why it matters

The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries.

TECHNICAL PATH

Attack & Exploitation Path

  1. 1

    Exposure — Required condition: an affected The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all up to, and inclu The Contact Form by Supsystic plugin for WordPress instance is reachable from a network position available to the attacker.

  2. 2

    Confirmed Initial trigger — attacker-controlled network input reaches the vulnerable function on the affected The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all service.

  3. 3

    Confirmed Exploit mechanism — the reported cross-site scripting is triggered inside The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all, crossing the security boundary described by the advisory or vulnerability record.

  4. 4

    Security outcome — Not publicly disclosed in enough detail to state a specific post-exploitation result without inference.

  5. 5

    Defender interruption point — Identify remotely reachable The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all up to, and inclu The Contact Form by Supsystic plugin for WordPress; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity.

DEFENDER ACTIONS

What security teams should check

  • Inventory affected products and versions.
  • Validate external and internal reachability of the vulnerable function.
  • Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
OPEN QUESTIONS

What is not yet confirmed

  • Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Continue reading

Related Cybersecurity News

More cybersecurity news
CyberDeltaForce publication standards