Germán Fernández[verified]@1ZRR4HDisclosure
The tweet discloses CVE-2026-4257, an unauthenticated Server Side Template Injection in Supsystic’s Contact Form that allows RCE (CVSS 9.8). It references a lab demonstration and provides a link, but offers no exploit code or evidence of active exploitation.
Orizon[verified]@OrizonCyberPatch
The tweet discloses a critical Server‑Side Template Injection flaw in the Supsystic Contact Form plugin, urging users to apply the patch immediately.
BreakGlass Intelligence[verified]@BreakGlassIntelGeneral
The post maps an offensive security platform, notes CVE-2024-48042 as a WordPress Contact Form RCE with CVSS 9.1, and indicates that CVE-2026-4257 is likely an internal designation; no PoC, exploit, patch, or active exploitation is cited.
Saeed Al Marri🇵🇸@S_A_M_912Disclosure
The post reports the discovery of CVE-2026-4257 affecting Supsystic versions up to 1.7.36, highlighting its RCE nature and critical CVSS score, without providing any PoC, exploit, or patch details.
Red Secure Tech Ltd.@redsecuretechExploit
The message advertises a WordPress Supsystic Contact Form SSTI vulnerability (CVE‑2026‑4257) that permits remote code execution via Twig template injection, and links to a blog that likely contains PoC code.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces CVE-2026-4257 for the Supsystic Contact Form WordPress plugin (<=1.7.36) as a server‑side template injection flaw, linking to a detection template but giving no exploit or patch details.
CVE@CVEnewDisclosure
The Supsystic Contact Form plugin for WordPress is vulnerable to Server‑Side Template Injection causing Remote Code Execution in all versions; no proof of concept, exploit, patch, or active exploitation is referenced.
0day Signal@0dayPublishingDisclosure
CVE-2026-4257 is an unauthenticated remote code execution vulnerability in the Supsystic WordPress contact form plugin, stemming from unsandboxed Twig templates and accessed via GET parameters. A vulnerability announcement with technical detail and a reference link is provided.