High severity7.2NVD Advisory· Published Apr 2, 2026· Updated Apr 15, 2026
CVE-2026-1540
CVE-2026-1540
Description
The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header
Affected products
1- Range: <1.2.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.