Stored Cross-Site Scripting Vulnerability in weForms Plugin for WordPress
CVE-2026-2707

6.4MEDIUM

What is CVE-2026-2707?

The weForms plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through its REST API endpoint, specifically during entry submission. This vulnerability occurs due to improper input sanitization between the frontend and the backend processes. Authenticated users with Subscriber or higher privileges can exploit this flaw by injecting malicious scripts into hidden fields of form submissions via the REST API endpoint. These scripts can execute when an administrator views the form entries, leading to potential data compromise and further security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

weForms – Easy Drag & Drop Contact Form Builder For WordPress * <= 1.6.27

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Sharief
.