Stored Cross-Site Scripting Vulnerability in WPForms Plugin by WordPress
CVE-2026-15782

4.9MEDIUM

What is CVE-2026-15782?

The WPForms – AI Form Builder for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping when integrating with OptinMonster. This allows authenticated users with contributor-level access or higher to inject malicious scripts into pages. These scripts execute whenever a user views the compromised page. Exploitation of this vulnerability necessitates that the OptinMonster plugin is both installed and properly configured with an active inline campaign that triggers specific markup on the affected page. As a result, it poses a significant risk to the security of web applications using this form builder plugin in conjunction with OptinMonster.

Affected Version(s)

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More 0 <= 2.0.0.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Asaf Mozes
.