Stored Cross-Site Scripting Vulnerability in FormCraft Plugin for WordPress
CVE-2026-7232

7.2HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-7232?

The FormCraft plugin for WordPress suffers from a vulnerability allowing Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. This issue allows unauthenticated attackers to inject arbitrary scripts into web pages, which then run when users visit those pages. The vulnerability arises from a failure to properly handle composite matrix sub-field keys during data storage and processing. Additionally, matrix values received from the server as arrays bypass important client-side validation checks and allow malicious content to be rendered in the DOM. The exploit can also occur through improperly handled array-typed field values, which, after submission, are incorrectly processed, potentially reinjecting harmful scripts.

Affected Version(s)

FormCraft 0 <= 3.9.14

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luc Huynh from Noventiq RedTeam
.