Description
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-08-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the FormGent WordPress plugin allows attackers to store malicious scripts in form submission fields. Once stored, the scripts execute in the browsers of any user who views the affected page, enabling defacement, cookie theft, or malicious redirects. The weakness stems from insufficient input sanitization and output escaping, classified as CWE‑79.

Affected Systems

Any WordPress site that has the FormGent – Next‑Gen AI Form Builder installed versions up to and including 1.9.2. The plugin is distributed by wpwax and is widely used for multi‑step forms, quizzes, and payment processing. Sites using earlier versions are also vulnerable until they upgrade.

Risk and Exploitability

The CVSS score of 7.2 indicates a high-severity flaw that is exploitable by unauthenticated actors. No EPSS score is listed, and the vulnerability is not part of the CISA KEV catalog, but the attack vector is the web interface, allowing an attacker to submit a crafted form without credentials. Once the payload is stored, any user visiting the page is impacted, giving potential attackers the ability to hijack sessions or deface content. Vigilance is required to detect and mitigate the stored code before it reaches users.

Generated by OpenCVE AI on August 6, 2026 at 13:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update FormGent to version 1.9.3 or later, which eliminates unsanitized input handling.
  • If an upgrade is impossible immediately, remove or sanitize all suspicious form entries from the database and temporarily disable the form feature until a patch is available.
  • Apply a content‑security‑policy that blocks inline scripts and restricts script sources, reducing the impact of any residual XSS vectors.

Generated by OpenCVE AI on August 6, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpwax
Wpwax formgent – Next-gen Ai Form Builder For Wordpress With Multi-step, Quizzes, Payments & More
Vendors & Products Wordpress
Wordpress wordpress
Wpwax
Wpwax formgent – Next-gen Ai Form Builder For Wordpress With Multi-step, Quizzes, Payments & More

Thu, 06 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpwax Formgent – Next-gen Ai Form Builder For Wordpress With Multi-step, Quizzes, Payments & More
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-06T14:09:26.212Z

Reserved: 2025-12-22T14:20:04.213Z

Link: CVE-2025-15028

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T13:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')