Detects WordPress installs running the Contact Form by Supsystic plugin at version 1.7.36 or earlier. The plugin renders form HTML through an unsandboxed Twig template engine, and the cfsPreFill feature passes user-supplied GET parameters into template expressions without escaping. An unauthenticated attacker can inject arbitrary Twig expressions via URL parameters to achieve server-side template injection and remote code execution.
Is your app exploitable through CVE-2026-4257?
Scan your domain free