A vulnerability classified as problematic was found in itpathsolutions Contact Form to Any API Plugin up to 3.0.6 on WordPress. Impacted is an unknown function. The manipulation of the argument cf7anyapi_form_field results in cross site scripting.

This vulnerability was named CVE-2026-15735. The attack may be performed from remote. There is no available exploit.