Reflected Cross-Site Scripting Flaw in WPForms Plugin for WordPress
CVE-2026-101921
4.7MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-101921?
The WPForms β AI Form Builder plugin for WordPress has a reflected cross-site scripting vulnerability via an attacker-controlled key parameter. This occurs due to inadequate input sanitization and output escaping in all versions up to and including 2.0.2.1. Attackers can exploit this vulnerability to inject malicious web scripts that execute when users interact with affected forms. Successful exploitation hinges on a site administrator having saved a form that includes a Smart Tag in an iframe srcdoc attribute and displaying the form description publicly.
Affected Version(s)
WPForms β AI Form Builder for WordPress β Contact Forms, Payment Forms, Survey Form, Quiz & More 0 <= 2.0.2.1