Stored Cross-Site Scripting Vulnerability in ARForms Plugin for WordPress
CVE-2026-3652
7.2HIGH
What is CVE-2026-3652?
The ARForms plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit stored Cross-Site Scripting (XSS) through the value parameter in the arf_save_incomplete_form_data AJAX action. This flaw stems from inadequate input sanitization and output escaping techniques. Consequently, malicious scripts can be injected, which may execute when an administrator accesses the 'Partial Filled Form Entries' page in the ARForms dashboard. It is crucial for website administrators to be aware of this vulnerability and implement necessary updates or mitigations to safeguard their environments.
Affected Version(s)
ARforms 0 <= 7.1.3