What the vulnerability does
01Description
The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_validate_form' AJAX endpoint allowing a user controlled parameter to set the 'from' email address. This makes it possible for unauthenticated attackers to send emails to arbitrary recipients utilizing the server. The information is limited to the contact form submission details.
Explanation of Vulnerability in Simple Terms
02Summary
Quick Contact Form versions 8.2.6 and earlier contain an input validation flaw that allows attackers to modify data integrity without authentication. The vulnerability affects the scope beyond the vulnerable component itself. No confidentiality or availability impact occurs, but attackers can alter information processed by the form.
What an attacker can do
03Attacker Capabilities
Modify or corrupt data processed by the contact form without needing to log in.
Potential impact on your site
04Site Impact
Form submissions may be altered or corrupted, potentially affecting data accuracy and user communications.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 17, 2026
CVE published
April 8, 2026
Record updated