CVE-2024-48042 CRITICAL

CVE-2024-48042: WordPress Contact Form by Supsystic plugin <= 1.7.28 - Remote Code Execution (RCE) vulnerability

Vendor Supsystic
Product Contact Form by Supsystic
Weakness CWE-82
Published October 16, 2024
Last update April 28, 2026

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.

Explanation of Vulnerability in Simple Terms

02Summary

Contact Form by Supsystic versions up to 1.7.28 contain a vulnerability that allows high-privilege users to read sensitive data, modify site content, or disrupt service across the entire application. The flaw requires administrator-level access to exploit and affects the scope beyond the vulnerable component itself. Site owners should update immediately to a version newer than 1.7.28.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify site content, or disrupt service if they have administrator access.

Potential impact on your site

04Site Impact

Administrators with malicious intent or compromised admin accounts can access all site data and modify or disable functionality.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level privileges on the site.

Key dates

06Disclosure timeline

October 16, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE