Unauthenticated Stored Cross-Site Scripting in HTML Forms Plugin for WordPress
CVE-2025-13861

6.1MEDIUM

What is CVE-2025-13861?

The HTML Forms – Simple WordPress Forms Plugin for WordPress is susceptible to unauthenticated stored cross-site scripting (XSS) due to inadequate sanitization of fabricated file upload field metadata. This vulnerability affects all versions up to and including 1.6.0. Attackers can exploit this by injecting arbitrary web scripts that execute within the WordPress admin dashboard whenever an administrator views the form submissions page. This can potentially lead to unauthorized administrative actions or data exposure.

Affected Version(s)

HTML Forms – Simple WordPress Forms Plugin * <= 1.6.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itthidej Aramsri
.
CVE-2025-13861 : Unauthenticated Stored Cross-Site Scripting in HTML Forms Plugin for WordPress