A vulnerability categorized as problematic has been discovered in code4life Database for CF7 Plugin up to 1.2.6 on WordPress. Affected by this vulnerability is the function serialize of the file /wp-json/contact-form-7/v1/contact-forms/{id}/feedback of the component REST API Endpoint. Such manipulation of the argument your-name[] leads to cross site scripting.

This vulnerability is listed as CVE-2026-13425. The attack may be performed from remote. There is no available exploit.