Stored Cross-Site Scripting Vulnerability in weForms Plugin for WordPress
CVE-2026-2707
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 March 2026
What is CVE-2026-2707?
The weForms plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through its REST API endpoint, specifically during entry submission. This vulnerability occurs due to improper input sanitization between the frontend and the backend processes. Authenticated users with Subscriber or higher privileges can exploit this flaw by injecting malicious scripts into hidden fields of form submissions via the REST API endpoint. These scripts can execute when an administrator views the form entries, leading to potential data compromise and further security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
weForms β Easy Drag & Drop Contact Form Builder For WordPress * <= 1.6.27
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved