Stored Cross-Site Scripting Vulnerability in FormCraft Plugin for WordPress
CVE-2026-7232
What is CVE-2026-7232?
The FormCraft plugin for WordPress suffers from a vulnerability allowing Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. This issue allows unauthenticated attackers to inject arbitrary scripts into web pages, which then run when users visit those pages. The vulnerability arises from a failure to properly handle composite matrix sub-field keys during data storage and processing. Additionally, matrix values received from the server as arrays bypass important client-side validation checks and allow malicious content to be rendered in the DOM. The exploit can also occur through improperly handled array-typed field values, which, after submission, are incorrectly processed, potentially reinjecting harmful scripts.
Affected Version(s)
FormCraft 0 <= 3.9.14