CVE-2026-57379

WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.


We have discovered 274 live websites that are affected by CVE-2026-57379.

Run a Free Instant Scan




Affected Software

Product  Social Contact Form
Category Wordpress Plugins
Vulnerable Domains274 live websites (86% of Social Contact Form install base)
Vulnerable Versions
  • from 0 through 2.15.3
Vulnerable Versions Count18 versions ( 86% of all versions)



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • dodoh4t | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-57379
United States48 websites



Brazil42 websites
India41 websites
Indonesia17 websites
Cyprus16 websites
Germany15 websites
GB11 websites
Italy9 websites
Argentina7 websites
Spain7 websites

Website Distribution by TLD

Number of websites using CVE-2026-57379
.com128 websites
.com.br41 websites
.it7 websites
.co.uk6 websites
.net6 websites
.ru4 websites
.es4 websites
.nl4 websites
.ca2 websites
.org2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-57379

Top websites that are affected by CVE-2026-57379. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.**.in India***,***
*****.***.br Brazil*,***,***
*********.***.br Brazil*,***,***
*********.com United States*,***,***
******.lk Sri Lanka*,***,***
**************.com Italy*,***,***
*****.ae United Arab Emirates*,***,***
******************.***.ar Argentina*,***,***
********.com Indonesia*,***,***
*********.com United States*,***,***
See full domain list

FAQ

A total of 274 websites have been identified as vulnerable to CVE-2026-57379, based on global website indexing conducted by WebTechSurvey.
The Social Contact Form is affected by the CVE-2026-57379 vulnerability.
Social Contact Form versions up to and including 2.15.3 are vulnerable to CVE-2026-57379.