Stored Cross-Site Scripting Vulnerability in WPForms Pro by WPMU DEV
CVE-2026-18409
What is CVE-2026-18409?
The WPForms Pro plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate sanitization of user inputs in Single Line Text and Paragraph Text fields. This flaw affects all versions up to and including 2.0.0.2, allowing unprivileged attackers to embed malicious web scripts. When users access a page with these injected scripts, the code executes, potentially compromising user sessions or stealing sensitive information. The vulnerability is exacerbated by the plugin's filtering mechanism, which improperly expands the 'post' allowance list to include iframe elements with a data-src attribute that bypasses standard URI validation, enabling harmful scripts to persist and execute on affected sites.
Affected Version(s)
WPForms Pro 0 <= 2.0.0.2