ConicPlex

Start Your Project

A dark home office desk at night lit by a monitor glowing WordPress blue and a warm desk lamp, with a flagged paper form sitting among developer clutter

On this Page

Zero Spam for WordPress Patches a Stored XSS Flaw in Its Contact Form 7 Integration (CVE-2026-96752)

Zero Spam for WordPress 5.7.11 patches a high-severity stored XSS flaw in its Contact Form 7 integration, tracked as CVE-2026-96752, exploitable without logging in.

Aftab Memon

September 25, 2026

Zero Spam for WordPress, an anti-spam plugin running on more than 30,000 sites, shipped version 5.7.11 on September 24, 2026 to fix a high-severity stored cross-site scripting bug tracked as CVE-2026-96752. The flaw affects every version up to and including 5.7.10 and lets an unauthenticated attacker plant a working script through the plugin’s Contact Form 7 integration, no login and no admin access needed. If your site runs Zero Spam alongside Contact Form 7, update now.

How the Contact Form 7 Bug Works

The bug sits in how Zero Spam logs submissions it decides are spam. When a Contact Form 7 request arrives without the plugin’s hidden zerospam_david_walsh_key field, Zero Spam flags it as spam and stores the raw submission, field names included, in the zerospam_log.submission_data database column. PHP will parse a field name written as a nested array, something like a bracketed key containing HTML, into an actual nested array key. Zero Spam saved that key as-is, without sanitizing it going in or escaping it coming back out.

That means an attacker doesn’t need an account, a CAPTCHA bypass, or repeated attempts. One crafted form submission is enough to store a script that fires the next time an admin opens the plugin’s detection log inside wp-admin.

Who Is Affected

Wordfence assigned the report a CVSS score of 7.2, high severity, and researcher Adrien Brunner is credited with finding it. Any WordPress site running Zero Spam below 5.7.11 with Contact Form 7 active is exposed, regardless of whether the two plugins are configured to work together on purpose. As of this writing, WPScan hasn’t recorded any public proof-of-concept exploit and the bug isn’t in CISA’s Known Exploited Vulnerabilities catalog, but disclosed WordPress plugin bugs tend to get probed within days, not months. Earlier this month a WordPress core XSS bug in wpautop() followed a similar pattern of quiet disclosure, and it’s the same story with a Forminator Forms vulnerability we covered last month: form-handling code is where a lot of these bugs keep turning up.

What to Do

  • Update Zero Spam for WordPress to 5.7.11 or later through your dashboard or WP-CLI as soon as you can.
  • If you can’t update immediately, disable Zero Spam’s Contact Form 7 integration in its settings until you do.
  • Before you trust any entries already sitting in the plugin’s detection log, check them for stored HTML or script tags rather than opening them straight in wp-admin.
  • If you manage several client sites running Zero Spam, patch all of them in the same pass rather than one at a time.

If you’re not sure what else is quietly sitting unpatched in your plugin stack, that’s exactly the kind of thing a WordPress Development audit is built to catch before it becomes a real incident.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

Illustration of a location pin with a service-radius ring and a banknote shape, representing restricting cash on delivery by pincode in WooCommerce

How to Restrict Cash on Delivery by Pincode in WooCommerce (3 Plugins Compared)

Three real plugins restrict WooCommerce Cash on Delivery by pincode or postcode, compared on price, requirements, and setup steps, with…

Sajil Memon

September 25, 2026

News & Updates

Monitor displaying a black and white geometric pattern split by a glowing red crack, symbolizing a critical flaw in Next.js ImageResponse

Next.js Patches a Critical Remote Code Execution Flaw in ImageResponse (CVE-2026-94545)

Next.js 16.3.6 patches CVE-2026-94545, a critical RCE in the Node.js ImageResponse API used to generate OG images. Here is who…

Sajil Memon

September 24, 2026

Plugins

Illustration of a package, clock, and location pin representing WooCommerce local pickup time slot scheduling

How to Add Pickup Time Slots to WooCommerce Checkout (4 Plugins Compared)

WooCommerce’s native Local Pickup has no time field. These 4 plugins add real pickup time slots to checkout, compared on…

Sajil Memon

September 24, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant