A vulnerability classified as problematic was found in 299Ko Contact Form Plugin. Affected is the function
_show_var of the file common/Template.php of the component Template Engine. Executing a manipulation of the argument name/firstname/email/message can lead to cross site scripting.
This vulnerability is handled as CVE-2026-71249. The attack can be executed remotely. There is not any exploit available.