CVE-2026-1540Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 104-0204-03
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1General1
2026-04-031
Disclosure1
Full discourse3 posts
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-1540: Spam Protect CF7 WordPress Plugin PHP Log RCE https://labs.cosmicbytez.ca/security/cve-2026-1540 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces CVE‑2026‑1540, a PHP Log remote code execution flaw in the Spam Protect CF7 WordPress plugin, providing basic technical details but lacking proof‑of‑concept, exploit, or active exploitation evidence.

    0000044
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1540 The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code… https://www.cve.org/CVERecord?id=CVE-2026-1540

    Post summary

    The post announces a new CVE (CVE‑2026‑1540) for the Spam Protect plugin, noting that a pre‑1.2.10 version permits PHP file logging that could lead to remote code execution by an editor‑level attacker.

    00000136
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1540 - Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution Intel Report: https://ift.tt/1DQJEi9

    Post summary

    The tweet flags CVE-2026-1540 as a Remote Code Execution vulnerability in older Spam Protect for Contact Form 7 versions, but offers no PoC, exploit details, patch info, or evidence of active exploitation.

    0000063
    281 followersView on X

Explore more