Stored Cross-Site Scripting Vulnerability in SureForms Contact Form Builder for WordPress
CVE-2026-18406
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-18406?
The SureForms plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. Attackers can exploit this vulnerability by injecting harmful web scripts that will execute when users access compromised pages. This affects all versions of the plugin up to and including 2.12.2, allowing unauthorized users to manipulate form fields and potentially compromise site security and user data.
Affected Version(s)
SureForms β Contact Form Builder, AI Forms, Payment Form, Survey & Quiz 0 <= 2.12.2