CVE-2026-12801 | mefic Ultra Addons for Contact Form 7 Plugin up to 3.5.43 on WordPress data-label/data-separator cross site scripting
A vulnerability was found in mefic Ultra Addons for Contact Form 7 Plugin up to 3.5.43 on WordPress. It has been classified as problematic. This impacts an unknown function. This manipulation of the argument data-label/data-separator causes cross site scripting.
This vulnerability appears as CVE-2026-12801. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More