Stored Cross-Site Scripting in SureForms Contact Form Plugin for WordPress
CVE-2026-7623
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-7623?
The SureForms plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'headingWrapper' parameter. This issue arises due to inadequate input sanitization and output escaping, enabling authenticated users with contributor-level access or higher to insert malicious scripts. These scripts can execute when a user accesses the affected page, potentially compromising user data and overall site integrity. It is crucial for users of SureForms to update to the latest version to mitigate this risk.
Affected Version(s)
SureForms β Contact Form Builder, AI Forms, Payment Form, Survey & Quiz 0 <= 2.8.1