CVE-2026-4257Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated attackers to execute arbitrary PHP functions and OS commands on the server by leveraging Twig's `registerUndefinedFilterCallback()` method to register arbitrary PHP callbacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-30); latest day: 1
  • 10 total mentions across 5 days

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-03-30: 3Mentions · 2026-03-31: 3Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-05-19: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-30: 3Technical Details · 2026-03-31: 3Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 1Technical Details · 2026-05-19: 103-3003-3104-0204-0305-19
Signal classification4 categories
Disclosure
770.0%
Patch
110.0%
General
110.0%
Exploit
110.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-303
Disclosure3
2026-03-313
Disclosure2Patch1
2026-04-022
Disclosure1General1
2026-04-031
Disclosure1
2026-05-191
Exploit1
Full discourse10 posts
  • Germán Fernández@1ZRR4H
    Disclosure

    📌 Server 111.90.158.78:8888 with #opendir exposes CVE-2026-4257 (LAB) + some targets 👁️ Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVSS 9.8 CRITICAL). Published 2 days ago. https://t.co/q4wNSmmYG8

    Post summary

    The tweet discloses CVE-2026-4257, an unauthenticated Server Side Template Injection in Supsystic’s Contact Form that allows RCE (CVSS 9.8). It references a lab demonstration and provides a link, but offers no exploit code or evidence of active exploitation.

    311178409.2K
    38.1K followersView on X
  • Saeed Al Marri🇵🇸@S_A_M_912
    Disclosure

    📌 الخادم 111.90.158.78:8888 مع #opendir يعرض CVE-2026-4257 (LAB) + بعض الأهداف 👁️ نموذج الاتصال من Supsystic < = 1.7.36 عدوى الجلد والأنسجة الرخوة غير الموثقة إلى RCE (CVSS 9.8 حرجة). نُشر قبل يومين

    Post summary

    The post reports the discovery of CVE-2026-4257 affecting Supsystic versions up to 1.7.36, highlighting its RCE nature and critical CVSS score, without providing any PoC, exploit, or patch details.

    00031684
    195 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Exploit

    A WordPress Supsystic Contact Form SSTI exploit (CVE-2026-4257)allows attackers to execute system commands via Twig template injection. https://www.redsecuretech.co.uk/blog/post/wordpress-supsystic-contact-form-ssti-exploit-cve-2026-4257/1193 #WordPress #Supsystic #ContactForm #SSTI #TwigInjection #CVE #RemoteCodeExecution #WordPressSecurity #InfoSec #Exploit https://t.co/8r2Ccc5gHl

    Post summary

    The message advertises a WordPress Supsystic Contact Form SSTI vulnerability (CVE‑2026‑4257) that permits remote code execution via Twig template injection, and links to a blog that likely contains PoC code.

    0101062
    61 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-4257 - critical 🚨 WordPress Contact Form by Supsystic - Server-Side Template Injection > Contact Form by Supsystic WordPress plugin <= 1.7.36 contains a server-side template ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-4257 @pdnuclei #NucleiTemplates...

    Post summary

    The tweet announces CVE-2026-4257 for the Supsystic Contact Form WordPress plugin (<=1.7.36) as a server‑side template injection flaw, linking to a detection template but giving no exploit or patch details.

    00020156
    905 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4257 The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, … https://www.cve.org/CVERecord?id=CVE-2026-4257

    Post summary

    The Supsystic Contact Form plugin for WordPress is vulnerable to Server‑Side Template Injection causing Remote Code Execution in all versions; no proof of concept, exploit, patch, or active exploitation is referenced.

    00001136
    56.9K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4257 — CVSS 9.8/10 ██████████ The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/sl5RaVVZUI

    Post summary

    The tweet discloses a critical Server‑Side Template Injection flaw in the Supsystic Contact Form plugin, urging users to apply the patch immediately.

    1000070
    11 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4257: Contact Form by Supsystic &lt;= 1.7.... Unauthenticated RCE via GET params exploiting unsandboxed Twig templates - WordPress sites running this plugin are sitti... https://zerodaysignal.com/vulnerability/CVE-2026-4257 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-4257 is an unauthenticated remote code execution vulnerability in the Supsystic WordPress contact form plugin, stemming from unsandboxed Twig templates and accessed via GET parameters. A vulnerability announcement with technical detail and a reference link is provided.

    00010124
    173 followersView on X
  • BreakGlass Intelligence@BreakGlassIntel
    General

    Quick run -> German's opendir → X5S SECURE COMMAND platform: Server went dark before we could dump it. But pivoting from that one dead IP we mapped: - X5S[.]US: Offensive security platform with XSS management, WordPress scanning, backup file discovery - CVE-2024-48042 (CVSS 9.1): WordPress Contact Form RCE. -The "CVE-2026-4257" from the tweet doesn't exist? it was an internal lab designation? - Multi-cloud: Cloudflare (3 separate accounts), Shinjiru Malaysia, OVH Canada, Tencent Cloud - Operator: "Crili Aprl", cirliaa@proton[.]me, UK WHOIS + US phone + Chinese platform = obfuscation deep dive pending 😎

    Post summary

    The post maps an offensive security platform, notes CVE-2024-48042 as a WordPress Contact Form RCE with CVSS 9.1, and indicates that CVE-2026-4257 is likely an internal designation; no PoC, exploit, patch, or active exploitation is cited.

    00000627
    559 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4257: CRITICAL] WordPress Contact Form plugin by Supsystic is susceptible to Server-Side Template Injection (SSTI), enabling Remote Code Execution (RCE). Attackers may exploit Twig engine vulnerabili...#cve,CVE-2026-4257,#cybersecurity https://cvefind.com/CVE-2026-4257

    Post summary

    The post announces CVE‑2026‑4257, a critical SSTI vulnerability in the Supsystic Contact Form plugin that allows remote code execution via the Twig engine.

    0000070
    608 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4257 - Critical The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.3... https://www.thehackerwire.com/vulnerability/CVE-2026-4257/ https://t.co/8PUGAKcQA8

    Post summary

    The post announces CVE-2026-4257, a critical SSTI vulnerability in the Supsystic Contact Form WordPress plugin that enables RCE in all releases up to version 1.7.3.

    0000067
    158 followersView on X

Explore more