Stored Cross-Site Scripting Vulnerability in ARForms Plugin for WordPress
CVE-2026-3652

7.2HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-3652?

The ARForms plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit stored Cross-Site Scripting (XSS) through the value parameter in the arf_save_incomplete_form_data AJAX action. This flaw stems from inadequate input sanitization and output escaping techniques. Consequently, malicious scripts can be injected, which may execute when an administrator accesses the 'Partial Filled Form Entries' page in the ARForms dashboard. It is crucial for website administrators to be aware of this vulnerability and implement necessary updates or mitigations to safeguard their environments.

Affected Version(s)

ARforms 0 <= 7.1.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PhĂş
.