module
Supsystic Contact Form Wordpress Plugin SSTI RCE
| Disclosed | Created |
|---|---|
| Mar 30, 2026 | May 26, 2026 |
Disclosed
Mar 30, 2026
Created
May 26, 2026
Description
This module performs SSTI achieving RCE in webpages containing the
Contact Form Wordpress plugin by Supsystic in versions 1.7.36 and
before.
Contact Form Wordpress plugin by Supsystic in versions 1.7.36 and
before.
Authors
Azril Fathoni
bootstrapbool [email protected]
bootstrapbool [email protected]
Platform
Linux,Unix,Windows
Architectures
cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.