A vulnerability classified as problematic was found in 299Ko Contact Form Plugin. Affected is the function _show_var of the file common/Template.php of the component Template Engine. Executing a manipulation of the argument name/firstname/email/message can lead to cross site scripting.

This vulnerability is handled as CVE-2026-71249. The attack can be executed remotely. There is not any exploit available.