Unauthenticated Stored Cross-Site Scripting in HTML Forms Plugin for WordPress
CVE-2025-13861
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 December 2025
What is CVE-2025-13861?
The HTML Forms β Simple WordPress Forms Plugin for WordPress is susceptible to unauthenticated stored cross-site scripting (XSS) due to inadequate sanitization of fabricated file upload field metadata. This vulnerability affects all versions up to and including 1.6.0. Attackers can exploit this by injecting arbitrary web scripts that execute within the WordPress admin dashboard whenever an administrator views the form submissions page. This can potentially lead to unauthorized administrative actions or data exposure.
Affected Version(s)
HTML Forms β Simple WordPress Forms Plugin * <= 1.6.0