Reflected Cross-Site Scripting Flaw in WPForms Plugin for WordPress
CVE-2026-101921

4.7MEDIUM

What is CVE-2026-101921?

The WPForms – AI Form Builder plugin for WordPress has a reflected cross-site scripting vulnerability via an attacker-controlled key parameter. This occurs due to inadequate input sanitization and output escaping in all versions up to and including 2.0.2.1. Attackers can exploit this vulnerability to inject malicious web scripts that execute when users interact with affected forms. Successful exploitation hinges on a site administrator having saved a form that includes a Smart Tag in an iframe srcdoc attribute and displaying the form description publicly.

Affected Version(s)

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More 0 <= 2.0.2.1

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO
.