# CVE-2026-77773

## Summary

- **CVE ID:** CVE-2026-77773
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** N/A
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 13, 2026

## Description

The Contact Form to Chat Apps | Click to Chat to Order  WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order  WordPress plugin before 2.15.8.

## Affected Products

- Unknown — Contact Form to Chat Apps | Click to Chat to Order (0)

## References

- [CNA](https://wpscan.com/vulnerability/c4c15701-2149-43b4-b794-38871c0dc734/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._