All verified exploits

CVE-2026-4257 Remote Code Execution via Twig Template Injection

Deterministic critical WordPress Added cve-verified-cve-2026-4257

Detects WordPress installs running the Contact Form by Supsystic plugin at version 1.7.36 or earlier. The plugin renders form HTML through an unsandboxed Twig template engine, and the cfsPreFill feature passes user-supplied GET parameters into template expressions without escaping. An unauthenticated attacker can inject arbitrary Twig expressions via URL parameters to achieve server-side template injection and remote code execution.

Related WordPress exploits

Is your app exploitable through CVE-2026-4257?

Scan your domain free