Unauthenticated Stored Cross-Site Scripting in HTML Forms Plugin for WordPress
CVE-2025-13861
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 December 2025
What is CVE-2025-13861?
The HTML Forms β Simple WordPress Forms Plugin for WordPress is susceptible to unauthenticated stored cross-site scripting (XSS) due to inadequate sanitization of fabricated file upload field metadata. This vulnerability affects all versions up to and including 1.6.0. Attackers can exploit this by injecting arbitrary web scripts that execute within the WordPress admin dashboard whenever an administrator views the form submissions page. This can potentially lead to unauthorized administrative actions or data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HTML Forms β Simple WordPress Forms Plugin * <= 1.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved