CVE-2026-83625 | Supsystic Contact Form by Supsystic Plugin up to 1.10.2 on WordPress IP Address Header updateNonce X-Forwarded-For cross site scripting
A vulnerability classified as problematic has been found in Supsystic Contact Form by Supsystic Plugin up to 1.10.2 on WordPress. Affected by this issue is the function updateNonce of the component IP Address Header. Performing a manipulation of the argument X-Forwarded-For results in cross site scripting.
This vulnerability is cataloged as CVE-2026-83625. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More